| From: | Álvaro Herrera <alvherre(at)kurilemu(dot)de> |
|---|---|
| To: | Daniel Gustafsson <daniel(at)yesql(dot)se> |
| Cc: | Vadim Shakirov <vadimsakirov5(at)gmail(dot)com>, pgsql-hackers(at)lists(dot)postgresql(dot)org |
| Subject: | Re: [PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack |
| Date: | 2026-09-30 11:59:25 |
| Message-ID: | arz4He4Cy_zEm6ip@alvherre.pgsql |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-hackers |
On 2026-Sep-30, Daniel Gustafsson wrote:
> I haven't read the patch, but reproducers of bugs are good to have. Is there a
> pattern which hits this out-of-bounds access?
Fun. I did this
(echo "int main() {" ; for i in `seq 1 256`; do echo "if ($i) "; done ; echo "switch (argc) {case 1: break;}}" ) > pgindent.c
which produced a smallish file:
$ ls -l pgindent.c
-rw-rw-r-- 1 alvherre alvherre 2497 Sep 30 13:52 pgindent.c
then ran pg_bsd_indent on it, which caused a segmentation fault and
ended with a somewhat larger file
$ ls -l pgindent.c
-rw-rw-r-- 1 alvherre alvherre 599314432 Sep 30 13:53 pgindent.c
That size was the entirety of the free disk space in that partition.
After applying this fix, it doesn't crash anymore, and merely dies with
a "Parser stack overflow" after having written up to "if (251)".
--
Álvaro Herrera PostgreSQL Developer — https://www.EnterpriseDB.com/
“Cuando no hay humildad las personas se degradan” (A. Christie)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Ashutosh Sharma | 2026-09-30 12:08:41 | Re: remote_apply commit hangs when wal_receiver_status_interval = 0 |
| Previous Message | Álvaro Herrera | 2026-09-30 11:48:05 | Re: REPACK (CONCURRENTLY) might keep dropped-column data |