pg.ddx.io  pgsql-committers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Michael Paquier <michael@paquier.xyz>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Reject too many arguments in CREATE TRIGGER
Date: Thu, 20 Aug 2026 00:39:10 +0000
Message-ID: <E1wwqoH-00000001I0b-1MPo@gemulon.postgresql.org> (raw)

Reject too many arguments in CREATE TRIGGER

The number of trigger arguments is stored as a smallint, but there was
no check that the number of arguments fits with the catalog data type.
This could result in an invalid negative value being stored once one
defined more than INT16_MAX arguments, with an overflowed value stored
in the catalogs.

Looking at other catalogs that store a number of arguments, we have
similar protections already in place (aggregates, functions, etc.).

Reported-by: Xingwang Xiang <v3rdant.xiang@gmail.com>
Author: Kyotaro Horiguchi <horikyota.ntt@gmail.com>
Discussion: https://postgr.es/m/19627-5b72a57e332e2b3f@postgresql.org
Backpatch-through: 14

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/259ca794c983772e5f8a321ad49c64f7d85d2c9f

Modified Files
--------------
src/backend/commands/trigger.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)



view thread (7+ messages)

Message-ID: <E1wwqoH-00000001I0b-1MPo@gemulon.postgresql.org>
Permalink:  ../E1wwqoH-00000001I0b-1MPo@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1wwqoH-00000001I0b-1MPo@gemulon.postgresql.org

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: michael@paquier.xyz, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Reject too many arguments in CREATE TRIGGER
  In-Reply-To: <E1wwqoH-00000001I0b-1MPo@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox