Re: Adding a range check on the sequence index from the publisher. - Mailing list pgsql-hackers

From Chao Li
Subject Re: Adding a range check on the sequence index from the publisher.
Date
Msg-id A111188F-321D-4D4C-88F3-F1FA46AFCEA8@gmail.com
Whole thread
In response to Adding a range check on the sequence index from the publisher.  (Masahiko Sawada <sawada.mshk@gmail.com>)
Responses Re: Adding a range check on the sequence index from the publisher.
List pgsql-hackers

> On Sep 22, 2026, at 03:51, Masahiko Sawada <sawada.mshk@gmail.com> wrote:
>
> Hi all,
> (CCing Amit as the committer of this feature)
>
> This was originally reported to pgsql-security by Anthropic OSS
> program but the security team considered it as a non-vuln bug since
> it's a v19-beta code, and I'm reporting here on behalf of them as it's
> permitted now.
>
> The reported problem is in sequencesync.c; the sequence
> synchronization worker uses an integer that came back from the
> publisher as a list subscript without checking it, and then writes
> through the resulting pointer.
>
> While it's not a problem in normal cases where the publisher is a
> normal PostgreSQL, it could lead to out-of-bounds writes when the
> publisher is a malicious server looking like a publisher.
>
> Other fields that we get through get_and_validate_seq_info() could
> also get the wrong value but they just show the wrong values rather
> than OOB writes. So I think we need a safeguard only for seqidx.
>
> I've attached the patch to fix it. Feedback is very welcome.
>
> Regards,
>
> --
> Masahiko Sawada
> Amazon Web Services: https://aws.amazon.com
> <v1-0001-Add-a-range-check-on-the-sequence-index-from-the-.patch>

If the concern here is a malicious publisher, does it also make sense to replace Assert(!isnull) with a runtime check
andfail if seqidx is NULL? 

Also there is a typo in the commit message:
```
which bounds-checks only under assertinos, so it was possible that an
```

assertinos -> assertions

Best regards,
--
Chao Li (Evan)
HighGo Software Co., Ltd.
https://www.highgo.com/







pgsql-hackers by date:

Previous
From: John Naylor
Date:
Subject: Re: Move system identifier generation to a common helper
Next
From: Bertrand Drouvot
Date:
Subject: Re: Report relation extension blockers within parallel lock groups