agora inbox for pgsql-bugs@postgresql.org  
help / color / mirror / Atom feed
BUG #19704: ispell dictionary accepts trailing junk in numeric COMPOUNDFLAG
2+ messages / 2 participants
[nested] [flat]

* BUG #19704: ispell dictionary accepts trailing junk in numeric COMPOUNDFLAG
@ 2026-09-19 13:51 PG Bug reporting form <noreply@postgresql.org>
  2026-09-20 16:18 ` Re: BUG #19704: ispell dictionary accepts trailing junk in numeric COMPOUNDFLAG Samriddha Kumar Tripathi <sumitkumartripathi0@gmail.com>
  0 siblings, 1 reply; 2+ messages in thread

From: PG Bug reporting form @ 2026-09-19 13:51 UTC (permalink / raw)
  To: pgsql-bugs@lists.postgresql.org; +Cc: imchifan@163.com

The following bug has been logged on the website:

Bug reference:      19704
Logged by:          Qifan Liu
Email address:      imchifan@163.com
PostgreSQL version: 18.6
Operating system:   Linux/amd64
Description:        

Creating an ispell text-search dictionary from an affix file containing
COMPOUNDFLAG 1x and FLAG num succeeds. PostgreSQL interprets the malformed
compound flag as numeric flag 1. This can cause subtle text-search behavior
in dictionaries installed from malformed affix files.

Steps to reproduce
------------------
Run as an operating-system user allowed to create files in PostgreSQL's
tsearch_data directory.

set -eu
sd=$(pg_config --sharedir)/tsearch_data
n=pg_numeric_compoundflag
printf 'SET UTF-8\nCOMPOUNDFLAG 1x\nFLAG num\n' > "$sd/$n.affix"
printf '2\nfoo/1\nbar/1\n' > "$sd/$n.dict"
psql -X -v ON_ERROR_STOP=1 -At postgres <<SQL
CREATE TEXT SEARCH DICTIONARY $n (
  TEMPLATE = ispell,
  DictFile = $n,
  AffFile = $n
);
SELECT coalesce(array_to_string(ts_lexize('$n', 'foo'), ','), 'NULL');
SQL

Actual result
-------------
Dictionary creation succeeds, and the malformed COMPOUNDFLAG value is
treated as flag 1:

CREATE TEXT SEARCH DICTIONARY
foo

Expected result
---------------
Dictionary creation should fail with a configuration-file error because "1x"
is not a valid numeric flag. PostgreSQL should not accept the prefix "1",
discard the trailing "x", and subsequently lexize the entry as flag 1.

Additional information
----------------------
The issue was reproduced on PostgreSQL 20devel, PostgreSQL 18.6, and
PostgreSQL 17.11.
Inference: numeric flag conversion validates the converted prefix or range
but does not verify that conversion consumed the entire token.








^ permalink  raw  reply  [nested|flat] 2+ messages in thread

* Re: BUG #19704: ispell dictionary accepts trailing junk in numeric COMPOUNDFLAG
  2026-09-19 13:51 BUG #19704: ispell dictionary accepts trailing junk in numeric COMPOUNDFLAG PG Bug reporting form <noreply@postgresql.org>
@ 2026-09-20 16:18 ` Samriddha Kumar Tripathi <sumitkumartripathi0@gmail.com>
  0 siblings, 0 replies; 2+ messages in thread

From: Samriddha Kumar Tripathi @ 2026-09-20 16:18 UTC (permalink / raw)
  To: imchifan@163.com; pgsql-bugs@lists.postgresql.org

Thanks for reporting the bug,

I reproduced this and verified the bug locally. Attached patch adds a check
to ensure the entire token is consumed (skipping trailing whitespace) after
strtol(), matching the existing error-handling style in the same function.
With the patch applied, the example above correctly fails with invalid
affix flag "1x".

I tested this manually: the malformed case above now errors, a normal valid
case (COMPOUNDFLAG 1) still works as before, and the full regression suite
passes (240/240). I haven't added a dedicated regression test for this yet,
because I was not sure if my patch was correct or in the right direction.
I'd be happy to implement changes and regression tests suggested.

Regards,
Samriddha

On Sun, Sep 20, 2026 at 4:35 PM PG Bug reporting form <
noreply@postgresql.org> wrote:

> The following bug has been logged on the website:
>
> Bug reference:      19704
> Logged by:          Qifan Liu
> Email address:      imchifan@163.com
> PostgreSQL version: 18.6
> Operating system:   Linux/amd64
> Description:
>
> Creating an ispell text-search dictionary from an affix file containing
> COMPOUNDFLAG 1x and FLAG num succeeds. PostgreSQL interprets the malformed
> compound flag as numeric flag 1. This can cause subtle text-search behavior
> in dictionaries installed from malformed affix files.
>
> Steps to reproduce
> ------------------
> Run as an operating-system user allowed to create files in PostgreSQL's
> tsearch_data directory.
>
> set -eu
> sd=$(pg_config --sharedir)/tsearch_data
> n=pg_numeric_compoundflag
> printf 'SET UTF-8\nCOMPOUNDFLAG 1x\nFLAG num\n' > "$sd/$n.affix"
> printf '2\nfoo/1\nbar/1\n' > "$sd/$n.dict"
> psql -X -v ON_ERROR_STOP=1 -At postgres <<SQL
> CREATE TEXT SEARCH DICTIONARY $n (
>   TEMPLATE = ispell,
>   DictFile = $n,
>   AffFile = $n
> );
> SELECT coalesce(array_to_string(ts_lexize('$n', 'foo'), ','), 'NULL');
> SQL
>
> Actual result
> -------------
> Dictionary creation succeeds, and the malformed COMPOUNDFLAG value is
> treated as flag 1:
>
> CREATE TEXT SEARCH DICTIONARY
> foo
>
> Expected result
> ---------------
> Dictionary creation should fail with a configuration-file error because
> "1x"
> is not a valid numeric flag. PostgreSQL should not accept the prefix "1",
> discard the trailing "x", and subsequently lexize the entry as flag 1.
>
> Additional information
> ----------------------
> The issue was reproduced on PostgreSQL 20devel, PostgreSQL 18.6, and
> PostgreSQL 17.11.
> Inference: numeric flag conversion validates the converted prefix or range
> but does not verify that conversion consumed the entire token.
>
>
>
>
>

Attachments:

  [text/x-patch] 0001-Reject-trailing-garbage-in-numeric-affix-flags.patch (941B, ../../CALLG_Vn5nyXmQRpP2agqKHzvbX3MSjafz0eQo+z1mSUEwehwog@mail.gmail.com/3-0001-Reject-trailing-garbage-in-numeric-affix-flags.patch)
  download | inline diff:
From 59ac47892adaeed065015a8ec9284743e1ea9c0b Mon Sep 17 00:00:00 2001
From: Samriddha Tripathi <sumitkumartripathi0@gmail.com>
Date: Sun, 20 Sep 2026 21:27:16 +0530
Subject: [PATCH] Reject trailing garbage in numeric affix flags

---
 src/backend/tsearch/spell.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/src/backend/tsearch/spell.c b/src/backend/tsearch/spell.c
index f2c6e06421..47a1ca07ac 100644
--- a/src/backend/tsearch/spell.c
+++ b/src/backend/tsearch/spell.c
@@ -1047,6 +1047,12 @@ parseNumericAffixFlag(const char *s)
 		ereport(ERROR,
 				(errcode(ERRCODE_CONFIG_FILE_ERROR),
 				 errmsg("invalid affix flag \"%s\"", s)));
+	while (isspace((unsigned char) *next))
+		next++;
+	if (*next != '\0')
+		ereport(ERROR,
+				(errcode(ERRCODE_CONFIG_FILE_ERROR),
+				 errmsg("invalid affix flag \"%s\"", s)));
 	if (i < 0 || i > FLAGNUM_MAXSIZE)
 		ereport(ERROR,
 				(errcode(ERRCODE_CONFIG_FILE_ERROR),
-- 
2.55.0



^ permalink  raw  reply  [nested|flat] 2+ messages in thread


end of thread, other threads:[~2026-09-20 16:18 UTC | newest]

Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-09-19 13:51 BUG #19704: ispell dictionary accepts trailing junk in numeric COMPOUNDFLAG PG Bug reporting form <noreply@postgresql.org>
2026-09-20 16:18 ` Samriddha Kumar Tripathi <sumitkumartripathi0@gmail.com>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox