Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x0WmK-004gNU-2Y for pgsql-bugs@arkaria.postgresql.org; Sun, 30 Aug 2026 04:04:20 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1x0WmJ-00CnCg-2M for pgsql-bugs@arkaria.postgresql.org; Sun, 30 Aug 2026 04:04:19 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x0WmJ-00CnCX-1V for pgsql-bugs@lists.postgresql.org; Sun, 30 Aug 2026 04:04:19 +0000 Received: from sss.pgh.pa.us ([68.162.161.243]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x0WmG-00000001z0O-3i0x for pgsql-bugs@lists.postgresql.org; Sun, 30 Aug 2026 04:04:19 +0000 Received: from sss1.sss.pgh.pa.us (localhost [127.0.0.1]) by sss.pgh.pa.us (8.18.1/8.18.1) with ESMTP id 67U447k7445120; Sun, 30 Aug 2026 00:04:07 -0400 From: Tom Lane To: Alexander Lakhin cc: Andrey Rachitskiy , michaelmalis2@gmail.com, pgsql-bugs@lists.postgresql.org Subject: Re: BUG #19595: Three memory-safety defects in src/backend/tsearch/spell.c (dictionary loader), PG 18.3 In-reply-to: <2ab10d25-7dc6-4914-8aea-ca0adfbe57c3@gmail.com> References: <19595-7dc18b4e212c4757@postgresql.org> <325748.1785691547@sss.pgh.pa.us> <0f3ddeb5-0dbd-479c-9d0e-ae254758e624@gmail.com> <336527.1785701494@sss.pgh.pa.us> <2ab10d25-7dc6-4914-8aea-ca0adfbe57c3@gmail.com> Comments: In-reply-to Alexander Lakhin message dated "Sun, 30 Aug 2026 07:00:00 +0300" MIME-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-ID: <445118.1788062647.1@sss.pgh.pa.us> Content-Transfer-Encoding: quoted-printable Date: Sun, 30 Aug 2026 00:04:07 -0400 Message-ID: <445119.1788062647@sss.pgh.pa.us> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Alexander Lakhin writes: > I discovered one more issue in this area. This OOM condition emulation: > --- a/src/backend/snowball/libstemmer/api.c > +++ b/src/backend/snowball/libstemmer/api.c > @@ -6,3 +6,3 @@ extern struct SN_env * SN_new_env(int alloc_size) > =C2=A0{ > -=C2=A0=C2=A0=C2=A0 struct SN_env * z =3D (struct SN_env *) malloc(alloc= _size); > +=C2=A0=C2=A0=C2=A0 struct SN_env * z =3D (rand() % 2 =3D=3D 0) ? NULL := (struct SN_env *) malloc(alloc_size); > =C2=A0=C2=A0=C2=A0=C2=A0 if (z =3D=3D NULL) return NULL; > leads to `make check` crashes like: Hmph. SN_new_env itself is visibly okay with this, so the failure is in some caller. I'm too tired to dig into it myself, but can you identify the culprit more precisely? regards, tom lane