pgpool: NULL-check json_get_value_for_key inputs and outputs in watchdo

From: Taiki Koshino <koshino(at)sraoss(dot)co(dot)jp>
To: pgpool-committers(at)lists(dot)postgresql(dot)org
Subject: pgpool: NULL-check json_get_value_for_key inputs and outputs in watchdo
Date: 2026-09-29 04:44:17
Message-ID: E1xBPhR-00000002h2V-1D4r@gothos.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgpool-committers

NULL-check json_get_value_for_key inputs and outputs in watchdog auth path.

A peer that opens a TCP connection to wd_port and sends a well-formed
WD_ADD_NODE_MESSAGE whose JSON body omits the "authkey" field reaches
verify_authhash_for_node() with authhash == NULL. When wd_authkey is
configured, the function calls strcmp(calculated_authhash, authhash)
unconditionally, faulting the watchdog process. Because PT_WATCHDOG is
respawned by the parent, an attacker can loop the request and deny all
cluster coordination (no failover, no quorum, no state transitions) for
as long as the connection is reachable.

The same shape exists one layer down in json_get_value_for_key(): the
function dereferences source->type without checking source first. Any
chained call of the form json_get_value_for_key(json_get_value_for_key(
root, "X"), "Y") -- where the inner lookup returns NULL because the
peer omitted the field -- crashes the watchdog the same way.

Add minimal NULL guards in both places:

* json_get_value_for_key() returns NULL when source is NULL, matching
the contract the existing callers (json_get_int_value_for_key,
json_get_string_value_for_key, etc.) already assume on its return
value.
* verify_authhash_for_node() rejects the peer with ereport(WARNING)
when the parsed authhash is NULL, so a missing authkey field is
treated as authentication failure rather than a crash.

Reported-by: Emond Papegaaij <emond(dot)papegaaij(at)topicus(dot)nl>
Reported-by: Claude
Author: Bo Peng <pengbo(at)sraoss(dot)co(dot)jp>
CVE-2026-92871
Backpatch-through: v4.3

Branch
------
V4_3_STABLE

Details
-------
https://git.postgresql.org/gitweb?p=pgpool2.git;a=commitdiff;h=bafccd4d2ce69263213bb72cb87d4bf5213cdb46

Modified Files
--------------
src/utils/json.c | 2 ++
src/watchdog/watchdog.c | 10 ++++++++++
2 files changed, 12 insertions(+)

Browse pgpool-committers by date

  From Date Subject
Next Message Taiki Koshino 2026-09-29 04:47:05 pgpool: Bound wd_nodes JSON array parsing in get_pool_config_from_json.
Previous Message Taiki Koshino 2026-09-29 04:43:57 pgpool: Fix operator precedence in parse_wd_node_function_json NodeIdLi