postgres.git / summary / log / commit / refs
commit b99b74144f9f37f39c38ca43b94a5ad46bb24a43
Author: Michael Paquier <michael@paquier.xyz>
Date: Thu Aug 20 00:38:23 2026 +0000
Reject too many arguments in CREATE TRIGGER
The number of trigger arguments is stored as a smallint, but there was
no check that the number of arguments fits with the catalog data type.
This could result in an invalid negative value being stored once one
defined more than INT16_MAX arguments, with an overflowed value stored
in the catalogs.
Looking at other catalogs that store a number of arguments, we have
similar protections already in place (aggregates, functions, etc.).
Reported-by: Xingwang Xiang <v3rdant.xiang@gmail.com>
Author: Kyotaro Horiguchi <horikyota.ntt@gmail.com>
Discussion: https://postgr.es/m/19627-5b72a57e332e2b3f@postgresql.org
Backpatch-through: 14
src/backend/commands/trigger.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index b7881bf4a29..8e1338d2c21 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -897,9 +897,16 @@ CreateTriggerFiringOn(const CreateTrigStmt *stmt, const char *queryString,
{
ListCell *le;
char *args;
- int16 nargs = list_length(stmt->args);
+ int nargs = list_length(stmt->args);
int len = 0;
+ Assert(nargs >= 0);
+ if (nargs > PG_INT16_MAX)
+ ereport(ERROR,
+ errcode(ERRCODE_TOO_MANY_ARGUMENTS),
+ errmsg("triggers cannot have more than %d arguments",
+ PG_INT16_MAX));
+
foreach(le, stmt->args)
{
char *ar = strVal(lfirst(le));