On Fri, 11 Sept 2026 at 00:11, PG Bug reporting form
<noreply@postgresql.org> wrote:
> `int8shl()` and `int8shr()` in `src/backend/utils/adt/int8.c` (lines
> 1255–1270) apply `arg1 << arg2` and `arg1 >> arg2` directly on `int64`
> without validating the shift amount `arg2`. Under C11 §6.5.7, shifting by a
> negative count, by a count ≥ 64, or left-shifting a signed value into
> overflow are all undefined behavior. Every other bigint arithmetic operator
> in PostgreSQL (`+`, `-`, `*`, unary `-`) raises `ERROR: bigint out of range`
> on overflow, making the shift operators the sole exception and creating a
> semantic inconsistency that can silently corrupt permission bitmasks or
> financial calculations.
There has been a documentation-only fix to mention that this behaviour
is intended in [1].
David
[1] https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5229d4b31