pg.ddx.io  pgsql-committers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Fujii Masao <fujii@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Use pg_parse_lsn() for server-supplied LSNs
Date: Fri, 21 Aug 2026 07:40:35 +0000
Message-ID: <E1wxJre-00000001U9Z-2SJ4@gemulon.postgresql.org> (raw)

Use pg_parse_lsn() for server-supplied LSNs

Commit d6bf0ab170 introduced pg_parse_lsn() to validate LSNs given on
the command line of pg_waldump, pg_recvlogical, and pg_receivewal.
The remaining sscanf("%X/%08X") call sites under src/bin parse LSNs
that arrive in server responses, timeline history files, and
backup_label files.  sscanf() accepts several forms that pg_lsn input
rejects and can silently continue with a different location than the
input text: a first component wider than eight hex digits wraps
around, a wider second component is truncated, and leading
whitespace, signs, "0x" prefixes, and trailing characters are
consumed or ignored.

Convert those call sites as well.  The two call sites that read a
location out of a longer line isolate it by temporarily terminating
the string at the next whitespace character, so that they can use
pg_parse_lsn() like the others.  Each tool keeps its existing error
message.

Malformed metadata now fails with each tool's existing error instead
of silently proceeding with a different location.  Two error paths
shift: pg_rewind's history-file parser now rejects trailing
characters attached to a switchpoint, which used to be ignored, and a
malformed backup_label location now fails pg_combinebackup's "could
not parse" check rather than its "improper terminator" check.

Author: Zexin Li <lizi.openmind@gmail.com>
Reviewed-by: Fujii Masao <masao.fujii@gmail.com>
Discussion: https://postgr.es/m/CAAP6ZkS_3OH3yhhAGK6vu+2V1C2Hv4K6SpRuZL415R-gxjdTSg@mail.gmail.com

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/f31d6fbc31d3b6901022e011942ac680d347d46a

Modified Files
--------------
src/bin/pg_basebackup/pg_basebackup.c   | 16 ++++----------
src/bin/pg_basebackup/receivelog.c      |  8 ++-----
src/bin/pg_basebackup/streamutil.c      | 12 +++--------
src/bin/pg_combinebackup/backup_label.c | 24 +++++++++++----------
src/bin/pg_rewind/libpq_source.c        |  7 ++-----
src/bin/pg_rewind/timeline.c            | 37 ++++++++++++++++++++++++++-------
6 files changed, 53 insertions(+), 51 deletions(-)



Message-ID: <E1wxJre-00000001U9Z-2SJ4@gemulon.postgresql.org>
Permalink:  ../E1wxJre-00000001U9Z-2SJ4@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1wxJre-00000001U9Z-2SJ4@gemulon.postgresql.org

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: fujii@postgresql.org, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Use pg_parse_lsn() for server-supplied LSNs
  In-Reply-To: <E1wxJre-00000001U9Z-2SJ4@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox