Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wvTzr-001J6g-23 for pgsql-bugs@arkaria.postgresql.org; Sun, 16 Aug 2026 06:05:28 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wvTzo-005O1r-10 for pgsql-bugs@arkaria.postgresql.org; Sun, 16 Aug 2026 06:05:25 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wvTzo-005O1j-02 for pgsql-bugs@lists.postgresql.org; Sun, 16 Aug 2026 06:05:25 +0000 Received: from fout-b7-smtp.messagingengine.com ([202.12.124.150]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wvTzl-000000010W3-3ZsX for pgsql-bugs@lists.postgresql.org; Sun, 16 Aug 2026 06:05:24 +0000 Received: from phl-compute-05.internal (phl-compute-05.internal [10.202.2.45]) by mailfout.stl.internal (Postfix) with ESMTP id 175551D000D2; Sun, 16 Aug 2026 02:05:20 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-05.internal (MEProxy); Sun, 16 Aug 2026 02:05:20 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paquier.xyz; h= cc:cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm3; t=1786860319; x=1786946719; bh=UGhta4wphT cpfVvT/wS/q75WlS54I5tT5KCIZA3u6C8=; b=tbmZ40hSYaDdEP7pMDGjOhE1YB dgCU4CGjGl37UFK4qKu3jS5pW8gvGNYhAA5JL6rGG/C+f6pz9ITfb8pPe1KEj0Ok C9bwTj9Z2ENnYXW7AJ/aLFXHAeYaZZtj7Kw29BfMc179vaULw9CeoHOgRzLk4kkD yOhPH37t2eVXma6fCb7LgGaqh0/7X/rjmzoXb8fG+ScFAK86u7aJ19K5riFhVlgR 930FO26nXmg5YREUfQuLfjPFHV58QVu4LKbdhLHTZ+roOr4ZdsEbSIp5A7Gh5fVm W4qrfkaVP1beZ17yzk9IHDLHGdjG/6vtQiPNwsFDhQR6H3A8OUD6/rGpZJ4w== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t= 1786860319; x=1786946719; bh=UGhta4wphTcpfVvT/wS/q75WlS54I5tT5KC IZA3u6C8=; b=PwFliW/K4LcpOG22ZE7ihSGB6/D3OV5J4lhwGkXOiREd3u9OYZI T5CSL6RR6ESA5jfkaUN6cjYPCsUU5Q3Gf2cDMUwI0796sRhL3Ud/v5PRww76o+15 X0zwGfye7ljevFPKF47tl8xY+RzkCKaaebivqT1rugFHZGR0zJaNhGXdK20CZRYS gx5suocf4Pf3PA3npK3wQWjKcJPWd2K4m6U0f4WQ4WwERMUnTjHYmTyyHn9Dqya+ lG8srqq0K7WkAo0qxjxgQrfADf2dzBTEu/Ipcx1nsanNE2ZQtYmGnw1THJwsgFTK MzTxnH7M2Xa1epYVFLVSYiD/v0VHlDDrGJA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTEsehzENlBEwbcFT2+SOM/lOjulf8QVNcyYYV5e44ZiozBaI5fQfOh2AnAFIQhbum Wuuf38Dxk51PDWDRaQqULbsX1x2E10aOSLBSqHIr5OXxWNjAX091S7mChyqCwpy/d476WI l3BSAXBRPDuJbtMZ25JoQYOXC/+Gf4vyOvo2oBrZapm9UxchxAqDYCDnYLLHwn6uqWf5HK ntQoMl8wmuR1z/JKhdo4wMk9OX1lStcV5xegordSR5RVGP3pf7C5eNzcn+oAyt8IimGHhE xlFhI/x7cBaCierxqCaxyYb/UbBuoDXUVKH5ZpLHo33JWOMb7RnV7dib8KPhnlfhtFemPA +sOIUptssE2iuHA6DH4k/19N5n/YRuRkImIcmaMurNiKxZ5d3D+a1elLE5rBs8rTHLMYiJ nrAyjQY44/2cVbgb2y92JabdTMXUQ1I5OOPo7Sk2oRopPxUBiHNtDX7L1vh0X7FNWh4bu2 MAfe9MyK1lxuxLSDGcjdBGhiAvuqLd+nBKD5nb06zP+d/xfmaRSOcMR2Wykaao17xKMOP0 LZCK5UROPwt6BaBNCoFAgmeK1Uywx7SyIsMp6pRlxoCeZPNPWxaZZm4v5fGbQHbgN+dnnS gVL/X0hlee7l5UKkPWSDe557b0sr+Dr4WU5MdJZ0vun4Ot/VYEZT80roYTng X-ME-Proxy: Feedback-ID: i0fe9450f:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sun, 16 Aug 2026 02:05:17 -0400 (EDT) Date: Sun, 16 Aug 2026 15:05:13 +0900 From: Michael Paquier To: Andrey Rachitskiy Cc: ilia.kashintsev@gmail.com, pgsql-bugs@lists.postgresql.org Subject: Re: BUG #19612: SEGV in ParseConfigFp() in guc-file.l Message-ID: References: <19612-24ccb4fc6da7786f@postgresql.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="XfFk/w/i23YUbNMt" Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --XfFk/w/i23YUbNMt Content-Type: multipart/mixed; boundary="lRBWcCNm+9OAtxae" Content-Disposition: inline --lRBWcCNm+9OAtxae Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Aug 13, 2026 at 02:00:58PM +0500, Andrey Rachitskiy wrote: > Thanks for review, and for catching the > yylex_init() warning. Sorry, I missed that one. Please do not top-post. Please see: https://en.wikipedia.org/wiki/Posting_style#Bottom-posting > The non-volatile copy for yylex_init() looks right. That call writes > through a yyscan_t *, so &scanner after the volatile change is exactly > the qualifier discard the compiler reports. Casting the address would > only silence the warning. scanner_init is never read after the > longjmp, so it does not need to be volatile. >=20 > I would drop the if (scanner) guard in cleanup. I don't follow this argument. ParseConfigFp(), ParseConfigFile() or ProcessConfigFile() can be called with an elevel lower than ERROR, and we have quite a few callers that do so. =20 It seems to me that we should also have a `goto cleanup` if yylex_init() fails, also pointing at d663f150b5ed that has switched the scanner to be reentrant where yylex_init() has been added. I have been on the edge about backpatching that, but as that's only v18, perhaps that's OK. It does not change the fact that the error reported is still confusing if one has the idea to use such a configuration layer, but I cannot really get convinced that this is worth tweaking: nobody is going to do that, so I don't really feel bad about letting flex complain as long as we handle the states accessed in the sigjumps in a better way. Thoughts or comments are welcome. -- Michael --lRBWcCNm+9OAtxae Content-Type: text/plain; charset=us-ascii Content-Disposition: attachment; filename=v2-0001-Fix-ASAN-failure-after-flex-errors-in-GUC-file-pa.patch Content-Transfer-Encoding: quoted-printable =46rom aa0bcbbbbe164671a73c9f0702c0fbcadb4a8da4 Mon Sep 17 00:00:00 2001 =46rom: Michael Paquier Date: Sun, 16 Aug 2026 14:49:16 +0900 Subject: [PATCH v2] Fix ASAN failure after flex errors in GUC file parsing As detected by ASAN, the scanner value used when parsing GUC files can be indeterminate when the flex error handler sigjumps to old cleanup path, before yylex_init() is called. The flex scanner state is now made volatile in ParseConfigFp(), since its value is assigned after sigsetjmp() and cna be accessed after siglongjmp(). yylex_init() cannot use a volatile pointer; a temporary variable is used before assigning the result of yylex_init() to it. Oversight in d663f150b5ed. Reported-by: Ilia Kashintsev Discussion: https://postgr.es/m/19612-24ccb4fc6da7786f@postgresql.org Backpatch-through: 18 --- src/backend/utils/misc/guc-file.l | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/src/backend/utils/misc/guc-file.l b/src/backend/utils/misc/guc= -file.l index 58669a67e050..84c102717eeb 100644 --- a/src/backend/utils/misc/guc-file.l +++ b/src/backend/utils/misc/guc-file.l @@ -354,7 +354,8 @@ ParseConfigFp(FILE *fp, const char *config_file, int de= pth, int elevel, unsigned int save_ConfigFileLineno =3D ConfigFileLineno; sigjmp_buf *save_GUC_flex_fatal_jmp =3D GUC_flex_fatal_jmp; sigjmp_buf flex_fatal_jmp; - yyscan_t scanner; + volatile yyscan_t scanner =3D NULL; + yyscan_t scanner_init =3D NULL; /* non-volatile for yylex_init() */ struct yyguts_t *yyg; /* needed for yytext macro */ volatile YY_BUFFER_STATE lex_buffer =3D NULL; int errorcount; @@ -384,8 +385,12 @@ ParseConfigFp(FILE *fp, const char *config_file, int d= epth, int elevel, ConfigFileLineno =3D 1; errorcount =3D 0; =20 - if (yylex_init(&scanner) !=3D 0) + if (yylex_init(&scanner_init) !=3D 0) + { elog(elevel, "yylex_init() failed: %m"); + goto cleanup; + } + scanner =3D scanner_init; yyg =3D (struct yyguts_t *) scanner; =20 lex_buffer =3D yy_create_buffer(fp, YY_BUF_SIZE, scanner); @@ -559,8 +564,11 @@ parse_error: } =20 cleanup: - yy_delete_buffer(lex_buffer, scanner); - yylex_destroy(scanner); + if (scanner) + { + yy_delete_buffer(lex_buffer, scanner); + yylex_destroy(scanner); + } /* Each recursion level must save and restore these static variables. */ ConfigFileLineno =3D save_ConfigFileLineno; GUC_flex_fatal_jmp =3D save_GUC_flex_fatal_jmp; --=20 2.55.0 --lRBWcCNm+9OAtxae-- --XfFk/w/i23YUbNMt Content-Type: application/pgp-signature; name=signature.asc -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEG72nH6vTowiyblFKnvQgOdbyQH0FAmqBUxkACgkQnvQgOdby QH2A+w//SFShVC3iX4wQMPhmge1UdMn86x6/Rn1KXhoEmOyK4GMmQIIKmvHRpCFO jVdXKX6fcgpBROlVJVYby7aCjUgGGIA52gZ21CRLPU5WOY3NBCbxQo3J7HDviQgE /aFIC3sgNjEcfGwzzDra4wBPqd6rbi/E0OWhaAcC/H2TtOErkA6cz8e2qpMEwXHE v8V98hcSxiuHsU6FNhZSUuU0x2b9MDnO3jwquMAIzx2zHrU3Rz63eGeLcPWFMj11 ZklX1ByMam9WhuwxvVwUOKw9B1dM1RO0NCFyP4ZcwumpAYl3LlF8kyh+XfOtyz7I 2XQEL7QHhrQP/TA/dqFErVVt2oKSxm0jCmnve+K2V1LYVAUw08BRJG9bmWclefWq RuCNqhBJY1W0P/n+89XDNxbVC8Hgm2b3PDqwb6WkmRLi0zHlc7MnbNUO50NydA71 fg5gI4EOOMxQks2+m5MEKHXI3Pw1SG3LrAQo36w39I7lH0gv7xGb4jZHbYoD0HZx sWa4dwDZil4j48sHfZ5wINpq0EXV2iatySufXpLgr4229Kul3mseUF4jea6oYuBW li6+t2R7BkpFVUKppYTgO3t8c5gsMt/L/cIpJWMGGDxHzYV7po11hXENR98QKBM3 zWxfbVpg3U1m0rVJe+LxM9h7pZs/KM1Sl+35qYrWVnBDtGEti8A= =M1iS -----END PGP SIGNATURE----- --XfFk/w/i23YUbNMt--