agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
pgsql: Fix integer overflow in nodeWindowAgg.c
6+ messages / 1 participants
[nested] [flat]

* pgsql: Fix integer overflow in nodeWindowAgg.c
@ 2026-04-09 10:37 Richard Guo <rguo@postgresql.org>
  0 siblings, 0 replies; 6+ messages in thread

From: Richard Guo @ 2026-04-09 10:37 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix integer overflow in nodeWindowAgg.c

In nodeWindowAgg.c, the calculations for frame start and end positions
in ROWS and GROUPS modes were performed using simple integer addition.
If a user-supplied offset was sufficiently large (close to INT64_MAX),
adding it to the current row or group index could cause a signed
integer overflow, wrapping the result to a negative number.

This led to incorrect behavior where frame boundaries that should have
extended indefinitely (or beyond the partition end) were treated as
falling at the first row, or where valid rows were incorrectly marked
as out-of-frame.  Depending on the specific query and data, these
overflows can result in incorrect query results, execution errors, or
assertion failures.

To fix, use overflow-aware integer addition (ie, pg_add_s64_overflow)
to check for overflows during these additions.  If an overflow is
detected, the boundary is now clamped to INT64_MAX.  This ensures the
logic correctly treats the boundary as extending to the end of the
partition.

Bug: #19405
Reported-by: Alexander Lakhin <exclusion@gmail.com>
Author: Richard Guo <guofenglinux@gmail.com>
Reviewed-by: Tender Wang <tndrwang@gmail.com>
Discussion: https://postgr.es/m/19405-1ecf025dda171555@postgresql.org
Backpatch-through: 14

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/8b6c89e377b545ddb04fc09eecf89cd52be89e07

Modified Files
--------------
src/backend/executor/nodeWindowAgg.c | 62 +++++++++++++++++++++---
src/test/regress/expected/window.out | 91 ++++++++++++++++++++++++++++++++++++
src/test/regress/sql/window.sql      | 26 +++++++++++
3 files changed, 172 insertions(+), 7 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix integer overflow in nodeWindowAgg.c
@ 2026-04-09 10:37 Richard Guo <rguo@postgresql.org>
  0 siblings, 0 replies; 6+ messages in thread

From: Richard Guo @ 2026-04-09 10:37 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix integer overflow in nodeWindowAgg.c

In nodeWindowAgg.c, the calculations for frame start and end positions
in ROWS and GROUPS modes were performed using simple integer addition.
If a user-supplied offset was sufficiently large (close to INT64_MAX),
adding it to the current row or group index could cause a signed
integer overflow, wrapping the result to a negative number.

This led to incorrect behavior where frame boundaries that should have
extended indefinitely (or beyond the partition end) were treated as
falling at the first row, or where valid rows were incorrectly marked
as out-of-frame.  Depending on the specific query and data, these
overflows can result in incorrect query results, execution errors, or
assertion failures.

To fix, use overflow-aware integer addition (ie, pg_add_s64_overflow)
to check for overflows during these additions.  If an overflow is
detected, the boundary is now clamped to INT64_MAX.  This ensures the
logic correctly treats the boundary as extending to the end of the
partition.

Bug: #19405
Reported-by: Alexander Lakhin <exclusion@gmail.com>
Author: Richard Guo <guofenglinux@gmail.com>
Reviewed-by: Tender Wang <tndrwang@gmail.com>
Discussion: https://postgr.es/m/19405-1ecf025dda171555@postgresql.org
Backpatch-through: 14

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/bfc7dff26d53ab42fe6cb6bc2243f5241a6df3e4

Modified Files
--------------
src/backend/executor/nodeWindowAgg.c | 62 +++++++++++++++++++++---
src/test/regress/expected/window.out | 91 ++++++++++++++++++++++++++++++++++++
src/test/regress/sql/window.sql      | 26 +++++++++++
3 files changed, 172 insertions(+), 7 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix integer overflow in nodeWindowAgg.c
@ 2026-04-09 10:37 Richard Guo <rguo@postgresql.org>
  0 siblings, 0 replies; 6+ messages in thread

From: Richard Guo @ 2026-04-09 10:37 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix integer overflow in nodeWindowAgg.c

In nodeWindowAgg.c, the calculations for frame start and end positions
in ROWS and GROUPS modes were performed using simple integer addition.
If a user-supplied offset was sufficiently large (close to INT64_MAX),
adding it to the current row or group index could cause a signed
integer overflow, wrapping the result to a negative number.

This led to incorrect behavior where frame boundaries that should have
extended indefinitely (or beyond the partition end) were treated as
falling at the first row, or where valid rows were incorrectly marked
as out-of-frame.  Depending on the specific query and data, these
overflows can result in incorrect query results, execution errors, or
assertion failures.

To fix, use overflow-aware integer addition (ie, pg_add_s64_overflow)
to check for overflows during these additions.  If an overflow is
detected, the boundary is now clamped to INT64_MAX.  This ensures the
logic correctly treats the boundary as extending to the end of the
partition.

Bug: #19405
Reported-by: Alexander Lakhin <exclusion@gmail.com>
Author: Richard Guo <guofenglinux@gmail.com>
Reviewed-by: Tender Wang <tndrwang@gmail.com>
Discussion: https://postgr.es/m/19405-1ecf025dda171555@postgresql.org
Backpatch-through: 14

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/f8736f8bc5315fe94cba961825acc3552f8064b0

Modified Files
--------------
src/backend/executor/nodeWindowAgg.c | 62 +++++++++++++++++++++---
src/test/regress/expected/window.out | 91 ++++++++++++++++++++++++++++++++++++
src/test/regress/sql/window.sql      | 26 +++++++++++
3 files changed, 172 insertions(+), 7 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix integer overflow in nodeWindowAgg.c
@ 2026-04-09 10:37 Richard Guo <rguo@postgresql.org>
  0 siblings, 0 replies; 6+ messages in thread

From: Richard Guo @ 2026-04-09 10:37 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix integer overflow in nodeWindowAgg.c

In nodeWindowAgg.c, the calculations for frame start and end positions
in ROWS and GROUPS modes were performed using simple integer addition.
If a user-supplied offset was sufficiently large (close to INT64_MAX),
adding it to the current row or group index could cause a signed
integer overflow, wrapping the result to a negative number.

This led to incorrect behavior where frame boundaries that should have
extended indefinitely (or beyond the partition end) were treated as
falling at the first row, or where valid rows were incorrectly marked
as out-of-frame.  Depending on the specific query and data, these
overflows can result in incorrect query results, execution errors, or
assertion failures.

To fix, use overflow-aware integer addition (ie, pg_add_s64_overflow)
to check for overflows during these additions.  If an overflow is
detected, the boundary is now clamped to INT64_MAX.  This ensures the
logic correctly treats the boundary as extending to the end of the
partition.

Bug: #19405
Reported-by: Alexander Lakhin <exclusion@gmail.com>
Author: Richard Guo <guofenglinux@gmail.com>
Reviewed-by: Tender Wang <tndrwang@gmail.com>
Discussion: https://postgr.es/m/19405-1ecf025dda171555@postgresql.org
Backpatch-through: 14

Branch
------
REL_16_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/0fe032e6a666173a587bdd207e13e68a5c20d180

Modified Files
--------------
src/backend/executor/nodeWindowAgg.c | 62 +++++++++++++++++++++---
src/test/regress/expected/window.out | 91 ++++++++++++++++++++++++++++++++++++
src/test/regress/sql/window.sql      | 26 +++++++++++
3 files changed, 172 insertions(+), 7 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix integer overflow in nodeWindowAgg.c
@ 2026-04-09 10:37 Richard Guo <rguo@postgresql.org>
  0 siblings, 0 replies; 6+ messages in thread

From: Richard Guo @ 2026-04-09 10:37 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix integer overflow in nodeWindowAgg.c

In nodeWindowAgg.c, the calculations for frame start and end positions
in ROWS and GROUPS modes were performed using simple integer addition.
If a user-supplied offset was sufficiently large (close to INT64_MAX),
adding it to the current row or group index could cause a signed
integer overflow, wrapping the result to a negative number.

This led to incorrect behavior where frame boundaries that should have
extended indefinitely (or beyond the partition end) were treated as
falling at the first row, or where valid rows were incorrectly marked
as out-of-frame.  Depending on the specific query and data, these
overflows can result in incorrect query results, execution errors, or
assertion failures.

To fix, use overflow-aware integer addition (ie, pg_add_s64_overflow)
to check for overflows during these additions.  If an overflow is
detected, the boundary is now clamped to INT64_MAX.  This ensures the
logic correctly treats the boundary as extending to the end of the
partition.

Bug: #19405
Reported-by: Alexander Lakhin <exclusion@gmail.com>
Author: Richard Guo <guofenglinux@gmail.com>
Reviewed-by: Tender Wang <tndrwang@gmail.com>
Discussion: https://postgr.es/m/19405-1ecf025dda171555@postgresql.org
Backpatch-through: 14

Branch
------
REL_15_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/4da71fc37a20eb7bfc339197ad6c9b95af46c59c

Modified Files
--------------
src/backend/executor/nodeWindowAgg.c | 62 +++++++++++++++++++++---
src/test/regress/expected/window.out | 91 ++++++++++++++++++++++++++++++++++++
src/test/regress/sql/window.sql      | 26 +++++++++++
3 files changed, 172 insertions(+), 7 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix integer overflow in nodeWindowAgg.c
@ 2026-04-09 10:37 Richard Guo <rguo@postgresql.org>
  0 siblings, 0 replies; 6+ messages in thread

From: Richard Guo @ 2026-04-09 10:37 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix integer overflow in nodeWindowAgg.c

In nodeWindowAgg.c, the calculations for frame start and end positions
in ROWS and GROUPS modes were performed using simple integer addition.
If a user-supplied offset was sufficiently large (close to INT64_MAX),
adding it to the current row or group index could cause a signed
integer overflow, wrapping the result to a negative number.

This led to incorrect behavior where frame boundaries that should have
extended indefinitely (or beyond the partition end) were treated as
falling at the first row, or where valid rows were incorrectly marked
as out-of-frame.  Depending on the specific query and data, these
overflows can result in incorrect query results, execution errors, or
assertion failures.

To fix, use overflow-aware integer addition (ie, pg_add_s64_overflow)
to check for overflows during these additions.  If an overflow is
detected, the boundary is now clamped to INT64_MAX.  This ensures the
logic correctly treats the boundary as extending to the end of the
partition.

Bug: #19405
Reported-by: Alexander Lakhin <exclusion@gmail.com>
Author: Richard Guo <guofenglinux@gmail.com>
Reviewed-by: Tender Wang <tndrwang@gmail.com>
Discussion: https://postgr.es/m/19405-1ecf025dda171555@postgresql.org
Backpatch-through: 14

Branch
------
REL_14_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/305cf0df0c7834a23d5ee22c0560970bb66d68eb

Modified Files
--------------
src/backend/executor/nodeWindowAgg.c | 62 +++++++++++++++++++++---
src/test/regress/expected/window.out | 91 ++++++++++++++++++++++++++++++++++++
src/test/regress/sql/window.sql      | 26 +++++++++++
3 files changed, 172 insertions(+), 7 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread


end of thread, other threads:[~2026-04-09 10:37 UTC | newest]

Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-04-09 10:37 pgsql: Fix integer overflow in nodeWindowAgg.c Richard Guo <rguo@postgresql.org>
2026-04-09 10:37 pgsql: Fix integer overflow in nodeWindowAgg.c Richard Guo <rguo@postgresql.org>
2026-04-09 10:37 pgsql: Fix integer overflow in nodeWindowAgg.c Richard Guo <rguo@postgresql.org>
2026-04-09 10:37 pgsql: Fix integer overflow in nodeWindowAgg.c Richard Guo <rguo@postgresql.org>
2026-04-09 10:37 pgsql: Fix integer overflow in nodeWindowAgg.c Richard Guo <rguo@postgresql.org>
2026-04-09 10:37 pgsql: Fix integer overflow in nodeWindowAgg.c Richard Guo <rguo@postgresql.org>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox