[PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack - Mailing list pgsql-hackers

From Vadim Shakirov
Subject [PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack
Date
Msg-id 20260930105134.568062-1-vadimsakirov5@gmail.com
Whole thread
Responses Re: [PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack
List pgsql-hackers
parser_state stores parser state in p_stack, il, and cstk, which
share the tos index.  The existing overflow check used p_stack, the
largest array, allowing out-of-bounds accesses to cstk and il.  Size
all three arrays equally.

Also widen the overflow check by one element: the lbrace case pushes
two entries (lbrace and then stmt), so there must be room for two
more elements when parse() is entered.
---
 src/tools/pg_bsd_indent/indent_globs.h | 4 ++--
 src/tools/pg_bsd_indent/parse.c        | 2 +-
 2 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/src/tools/pg_bsd_indent/indent_globs.h b/src/tools/pg_bsd_indent/indent_globs.h
index 917961bd3d6..e88dd52c891 100644
--- a/src/tools/pg_bsd_indent/indent_globs.h
+++ b/src/tools/pg_bsd_indent/indent_globs.h
@@ -234,8 +234,8 @@ extern int   ifdef_level;
 struct parser_state {
     int         last_token;
     int         p_stack[256];    /* this is the parsers stack */
-    int         il[64];        /* this stack stores indentation levels */
-    float       cstk[32];    /* used to store case stmt indentation levels */
+    int         il[256];        /* this stack stores indentation levels */
+    float       cstk[256];    /* used to store case stmt indentation levels */
     int         box_com;    /* set to true when we are in a "boxed"
                  * comment. In that case, the first non-blank
                  * char should be lined up with the / in / followed by * */
diff --git a/src/tools/pg_bsd_indent/parse.c b/src/tools/pg_bsd_indent/parse.c
index 94cea724393..f50a03193e1 100644
--- a/src/tools/pg_bsd_indent/parse.c
+++ b/src/tools/pg_bsd_indent/parse.c
@@ -203,7 +203,7 @@ parse(int tk) /* tk: the code for the construct scanned */
 
     }                /* end of switch */
 
-    if (ps.tos >= nitems(ps.p_stack) - 1)
+    if (ps.tos >= nitems(ps.p_stack) - 2)
     errx(1, "Parser stack overflow");
 
     reduce();            /* see if any reduction can be done */
-- 
2.43.0




pgsql-hackers by date:

Previous
From: Etsuro Fujita
Date:
Subject: Re: Typo in version check in postgresAcquireSampleRowsFunc
Next
From: jian he
Date:
Subject: Re: on_error table, saving error info to a table