pg.ddx.io  pgsql-bugs@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Michael Paquier <michael@paquier.xyz>
To: Tom Lane <tgl@sss.pgh.pa.us>
Cc: Robin Haberkorn <haberkorn@b1-systems.de>
Cc: Jim Jones <jim.jones@uni-muenster.de>
Cc: pgsql-bugs@lists.postgresql.org
Cc: maralist86@mail.ru
Subject: Re: BUG #18943: Return value of a function 'xmlBufferCreate' is dereferenced at xpath.c:177 without checking for NUL
Date: Wed, 9 Jul 2025 09:45:07 +0900
Message-ID: <aG27k8a2y9fvak40@paquier.xyz> (raw)
In-Reply-To: <689495.1751981797@sss.pgh.pa.us>
References: <aEEingzOta_S_Nu7@paquier.xyz>
	<CAPLXN34Dr3Gbi+xJ6BgCeTyBJkMVe3cn7qxoADV72rC9ZHeBtQ@mail.gmail.com>
	<d2410ca0-c0dd-4f63-9e70-3d7a62a5d705@uni-muenster.de>
	<b35e2342-0f02-4365-94cf-55052ac9bda1@uni-muenster.de>
	<aEKCoNIfLxjyKY3r@paquier.xyz>
	<31f3480e-cd7d-4021-b392-87922572cc37@uni-muenster.de>
	<aETzMep2fGfB0AIp@paquier.xyz>
	<DB6KVQ60OJ8X.A8LWANY82NLG@b1-systems.de>
	<aGz_ssvep-q7oM-M@paquier.xyz>
	<689495.1751981797@sss.pgh.pa.us>

On Tue, Jul 08, 2025 at 09:36:37AM -0400, Tom Lane wrote:
> The comment in xml_errorHandler() argues

Yep.

> So switching to _ALL (or even _WELL_FORMED) mode would result in
> nontrivial differences in the behavior of xpath.c's functions with
> bad input.  Maybe that's a reasonable thing to do, but it's a
> question of user-visible behavior not just code cleanliness.

Yes, I don't see a huge advantage in doing the switch for this module.
If the gain in information in the error states grabbed from libxml2
makes it a win, that may be a different argument (I am fine to be
proved wrong), but I cannot get excited about that without more
data to claim it so.

I have quickly tested the change, and the xpath_string() path was one
area that immediately stood out, and we may report an incorrect error.
--
Michael

Attachments:

  [application/pgp-signature] signature.asc (832B, ../aG27k8a2y9fvak40@paquier.xyz/2-signature.asc)
  download

view thread (27+ messages)  latest in thread

Message-ID: <aG27k8a2y9fvak40@paquier.xyz>
Permalink:  ../aG27k8a2y9fvak40@paquier.xyz/
Also on:    postgresql.org/message-id/aG27k8a2y9fvak40@paquier.xyz

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: michael@paquier.xyz, tgl@sss.pgh.pa.us, haberkorn@b1-systems.de, jim.jones@uni-muenster.de, pgsql-bugs@lists.postgresql.org, maralist86@mail.ru
  Subject: Re: BUG #18943: Return value of a function 'xmlBufferCreate' is dereferenced at xpath.c:177 without checking for NUL
  In-Reply-To: <aG27k8a2y9fvak40@paquier.xyz>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox