agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
pgsql: Fix incremental JSON parser numeric token reassembly across chun
3+ messages / 1 participants
[nested] [flat]

* pgsql: Fix incremental JSON parser numeric token reassembly across chun
@ 2026-04-10 13:32  Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 3+ messages in thread

From: Andrew Dunstan @ 2026-04-10 13:32 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix incremental JSON parser numeric token reassembly across chunks.

When the incremental JSON parser splits a numeric token across chunk
boundaries, it accumulates continuation characters into the partial
token buffer.  The accumulator's switch statement unconditionally
accepted '+', '-', '.', 'e', and 'E' as valid numeric continuations
regardless of position, which violated JSON number grammar
(-? int [frac] [exp]).  For example, input "4-" fed in single-byte
chunks would accumulate the '-' into the numeric token, producing an
invalid token that later triggered an assertion failure during
re-lexing.

Fix by tracking parser state (seen_dot, seen_exp, prev character)
across the existing partial token and incoming bytes, so that each
character class is accepted only in its grammatically valid position.

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/2478bd5db0aad3599802636201af7adc170ba280

Modified Files
--------------
src/common/jsonapi.c | 61 ++++++++++++++++++++++++++++++++++++++++++++++------
1 file changed, 55 insertions(+), 6 deletions(-)



^ permalink  raw  reply  [nested|flat] 3+ messages in thread

* pgsql: Fix incremental JSON parser numeric token reassembly across chun
@ 2026-04-10 14:21  Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 3+ messages in thread

From: Andrew Dunstan @ 2026-04-10 14:21 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix incremental JSON parser numeric token reassembly across chunks.

When the incremental JSON parser splits a numeric token across chunk
boundaries, it accumulates continuation characters into the partial
token buffer.  The accumulator's switch statement unconditionally
accepted '+', '-', '.', 'e', and 'E' as valid numeric continuations
regardless of position, which violated JSON number grammar
(-? int [frac] [exp]).  For example, input "4-" fed in single-byte
chunks would accumulate the '-' into the numeric token, producing an
invalid token that later triggered an assertion failure during
re-lexing.

Fix by tracking parser state (seen_dot, seen_exp, prev character)
across the existing partial token and incoming bytes, so that each
character class is accepted only in its grammatically valid position.

Backpatch-through: 17

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/2e373785ec07102badee139236ac78c4da4f7c16

Modified Files
--------------
src/common/jsonapi.c | 55 ++++++++++++++++++++++++++++++++++++++++++++++++++--
1 file changed, 53 insertions(+), 2 deletions(-)



^ permalink  raw  reply  [nested|flat] 3+ messages in thread

* pgsql: Fix incremental JSON parser numeric token reassembly across chun
@ 2026-04-10 14:21  Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 3+ messages in thread

From: Andrew Dunstan @ 2026-04-10 14:21 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix incremental JSON parser numeric token reassembly across chunks.

When the incremental JSON parser splits a numeric token across chunk
boundaries, it accumulates continuation characters into the partial
token buffer.  The accumulator's switch statement unconditionally
accepted '+', '-', '.', 'e', and 'E' as valid numeric continuations
regardless of position, which violated JSON number grammar
(-? int [frac] [exp]).  For example, input "4-" fed in single-byte
chunks would accumulate the '-' into the numeric token, producing an
invalid token that later triggered an assertion failure during
re-lexing.

Fix by tracking parser state (seen_dot, seen_exp, prev character)
across the existing partial token and incoming bytes, so that each
character class is accepted only in its grammatically valid position.

Backpatch-through: 17

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/3e4955630292a7eb38f5fb3c6c5685623088ffd1

Modified Files
--------------
src/common/jsonapi.c | 61 ++++++++++++++++++++++++++++++++++++++++++++++------
1 file changed, 55 insertions(+), 6 deletions(-)



^ permalink  raw  reply  [nested|flat] 3+ messages in thread


end of thread, other threads:[~2026-04-10 14:21 UTC | newest]

Thread overview: 3+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-04-10 13:32 pgsql: Fix incremental JSON parser numeric token reassembly across chun Andrew Dunstan <andrew@dunslane.net>
2026-04-10 14:21 pgsql: Fix incremental JSON parser numeric token reassembly across chun Andrew Dunstan <andrew@dunslane.net>
2026-04-10 14:21 pgsql: Fix incremental JSON parser numeric token reassembly across chun Andrew Dunstan <andrew@dunslane.net>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox