Re: [PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack - Mailing list pgsql-hackers

From Álvaro Herrera
Subject Re: [PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack
Date
Msg-id arz4He4Cy_zEm6ip@alvherre.pgsql
Whole thread
In response to Re: [PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack  (Daniel Gustafsson <daniel@yesql.se>)
Responses Re: [PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack
List pgsql-hackers
On 2026-Sep-30, Daniel Gustafsson wrote:

> I haven't read the patch, but reproducers of bugs are good to have.  Is there a
> pattern which hits this out-of-bounds access?

Fun.  I did this

(echo "int main() {" ; for i in `seq 1 256`; do echo "if ($i) "; done ; echo "switch (argc) {case 1: break;}}" ) >
pgindent.c

which produced a smallish file:
$ ls -l pgindent.c
-rw-rw-r-- 1 alvherre alvherre 2497 Sep 30 13:52 pgindent.c

then ran pg_bsd_indent on it, which caused a segmentation fault and
ended with a somewhat larger file

$ ls -l pgindent.c
-rw-rw-r-- 1 alvherre alvherre 599314432 Sep 30 13:53 pgindent.c

That size was the entirety of the free disk space in that partition.

After applying this fix, it doesn't crash anymore, and merely dies with
a "Parser stack overflow" after having written up to "if (251)".

-- 
Álvaro Herrera         PostgreSQL Developer  —  https://www.EnterpriseDB.com/
“Cuando no hay humildad las personas se degradan” (A. Christie)



pgsql-hackers by date:

Previous
From: Álvaro Herrera
Date:
Subject: Re: REPACK (CONCURRENTLY) might keep dropped-column data
Next
From: Ashutosh Sharma
Date:
Subject: Re: remote_apply commit hangs when wal_receiver_status_interval = 0