pgsql: Reject "23:59:60.nnn" in datetime input.

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Reject "23:59:60.nnn" in datetime input.
Date: 2020-06-04 20:42:42
Message-ID: E1jgwhG-0002Cv-Cn@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Reject "23:59:60.nnn" in datetime input.

It's intentional that we don't allow values greater than 24 hours,
while we do allow "24:00:00" as well as "23:59:60" as inputs.
However, the range check was miscoded in such a way that it would
accept "23:59:60.nnn" with a nonzero fraction. For time or timetz,
the stored result would then be greater than "24:00:00" which would
fail dump/reload, not to mention possibly confusing other operations.

Fix by explicitly calculating the result and making sure it does not
exceed 24 hours. (This calculation is redundant with what will happen
later in tm2time or tm2timetz. Maybe someday somebody will find that
annoying enough to justify refactoring to avoid the duplication; but
that seems too invasive for a back-patched bug fix, and the cost is
probably unmeasurable anyway.)

Note that this change also rejects such input as the time portion
of a timestamp(tz) value.

Back-patch to v10. The bug is far older, but to change this pre-v10
we'd need to ensure that the logic behaves sanely with float timestamps,
which is possibly nontrivial due to roundoff considerations.
Doesn't really seem worth troubling with.

Per report from Christoph Berg.

Discussion: https://postgr.es/m/20200520125807.GB296739@msg.df7cb.de

Branch
------
REL_11_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/6490376e56b09befe3d4e6792beb1d2328b61b44

Modified Files
--------------
src/backend/utils/adt/date.c | 70 ++++++++++++++++++++++++++++++++----
src/backend/utils/adt/datetime.c | 23 +++---------
src/backend/utils/adt/timestamp.c | 17 +++------
src/include/utils/date.h | 2 ++
src/test/regress/expected/time.out | 41 +++++++++++++++++++++
src/test/regress/expected/timetz.out | 41 +++++++++++++++++++++
src/test/regress/sql/time.sql | 10 ++++++
src/test/regress/sql/timetz.sql | 10 ++++++
8 files changed, 176 insertions(+), 38 deletions(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Tom Lane 2020-06-04 21:57:36 pgsql: Add missing #include.
Previous Message Peter Eisentraut 2020-06-04 20:11:58 pgsql: psql: Clean up terminology in \dAp command