pgsql: Reject CR and LF characters in backup labels

From: Michael Paquier <michael(at)paquier(dot)xyz>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Reject CR and LF characters in backup labels
Date: 2026-10-05 03:48:13
Message-ID: E1xDZgT-00000000Lwn-00DE@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Reject CR and LF characters in backup labels

The label is written as one line of the backup_label file. A label
with a newline added extra lines to the file, and recovery could read
those as other fields, failing on them. Characters could also be
injected to make recovery behave in inconsistent ways.

Trying to use such characters in label names is now rejected, for both
pg_backup_start() and BASE_BACKUP.

As this is arguably a behavior change, no backpatch is done. I also
seriously doubt that anybody is relying on the behavior of pushing some
arbitrary data to backup_label files, and even if they do, it would be a
very bad idea to contradict what the backend decides to generate.

Reported-by: Shallow <theshallow27(at)gmail(dot)com>
Author: Shihao Zhong <zhong950419(at)gmail(dot)com>
Discussion: https://postgr.es/m/19730-85a6044c9e72774a@postgresql.org

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/e624e1fd13dcc754deebfd8a5be8f6fa578e17da

Modified Files
--------------
src/backend/access/transam/xlog.c | 5 +++++
src/test/recovery/t/020_archive_status.pl | 13 +++++++++++++
2 files changed, 18 insertions(+)

Browse pgsql-committers by date

  From Date Subject
Next Message Fujii Masao 2026-10-05 04:04:35 pgsql: Stabilize recovery conflict count checks in 031_recovery_conflic
Previous Message David Rowley 2026-10-05 02:59:04 pgsql: Use tuplestore_clear instead of tuplestore_end in nodeTableFuncs