Re: BUG #19672: int8shl/int8shr Undefined Behavior on Out-of-Range Shift Amounts - Mailing list pgsql-bugs

From David Rowley
Subject Re: BUG #19672: int8shl/int8shr Undefined Behavior on Out-of-Range Shift Amounts
Date
Msg-id CAApHDvpLyFmTL-LmOBucG42Zz+3ytkSFGAJsbohVhVS2eydQxQ@mail.gmail.com
Whole thread
List pgsql-bugs
On Fri, 11 Sept 2026 at 00:11, PG Bug reporting form
<noreply@postgresql.org> wrote:
> `int8shl()` and `int8shr()` in `src/backend/utils/adt/int8.c` (lines
> 1255–1270) apply `arg1 << arg2` and `arg1 >> arg2` directly on `int64`
> without validating the shift amount `arg2`. Under C11 §6.5.7, shifting by a
> negative count, by a count ≥ 64, or left-shifting a signed value into
> overflow are all undefined behavior. Every other bigint arithmetic operator
> in PostgreSQL (`+`, `-`, `*`, unary `-`) raises `ERROR: bigint out of range`
> on overflow, making the shift operators the sole exception and creating a
> semantic inconsistency that can silently corrupt permission bitmasks or
> financial calculations.

There has been a documentation-only fix to mention that this behaviour
is intended in [1].

David

[1] https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5229d4b31



pgsql-bugs by date:

Previous
From: Daniel Gustafsson
Date:
Subject: Re: autovacuum: automatically propagate updated parameters
Next
From: shihao zhong
Date:
Subject: Re: BUG #19705: One NaN box makes a BRIN box_inclusion_ops index omit unrelated rows