agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
From: Daniel Gustafsson <dgustafsson@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Handle PG_INT32_MIN negation overflow in right()
Date: Tue, 01 Sep 2026 08:21:05 +0000
Message-ID: <E1x1Jjs-000000030c9-37hF@gemulon.postgresql.org> (raw)

Handle PG_INT32_MIN negation overflow in right()

A negative n means "return all but the first |n| characters", so
text_right() negates n before clipping.  Negating PG_INT32_MIN
overflows; with -fwrapv the result is PG_INT32_MIN again, still
negative, and pg_mbcharcliplen() then returns an offset of zero,
so the whole string is returned where the correct answer is an
empty string:

  SELECT right('abcdef', (-2147483648)::int4); -- 'abcdef', want ''
  SELECT right('abcdef', -2147483647);         -- '', correct

Clamp to PG_INT32_MAX instead.  Any n whose absolute value is at
least the string's length skips all of it, and a text value cannot
be longer than PG_INT32_MAX, so this gives the same answer for every
other input.  Erroring out, as text_format_string_conversion() does
for a width of INT_MIN, would not be correct here: unlike a format
width, an out-of-range skip count has a well-defined result.

Using pg_neg_s32_overflow() would be a slightly more optimal fix but
as it's only available in PostgreSQL 18 and later the decision was
taken to apply the same fix to all backbranches.

Backpatch to all supported versions.

Author: Ewan Young <kdbase.hack@gmail.com>
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
Reviewed-by: Dagfinn Ilmari Mannsåker <ilmari@ilmari.org>
Reviewed-by: David Rowley <dgrowleyml@gmail.com>
Reviewed-by: Chao Li <li.evan.chao@gmail.com>
Discussion: https://postgr.es/m/CAON2xHNnBz-AcPJgDmd5_39+8qR5AUKEZk4X3ZM-0zdsATn8kQ@mail.gmail.com
Backpatch-through: 14

Branch
------
REL_16_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/48af47dcdd591d8deb0bd4d14652780d165ca879

Modified Files
--------------
src/backend/utils/adt/varlena.c    | 12 +++++++++++-
src/test/regress/expected/text.out |  8 ++++++++
src/test/regress/sql/text.sql      |  3 +++
3 files changed, 22 insertions(+), 1 deletion(-)



view thread (6+ messages)  latest in thread

Message-ID: <E1x1Jjs-000000030c9-37hF@gemulon.postgresql.org>
Permalink:  ../E1x1Jjs-000000030c9-37hF@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1x1Jjs-000000030c9-37hF@gemulon.postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: dgustafsson@postgresql.org, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Handle PG_INT32_MIN negation overflow in right()
  In-Reply-To: <E1x1Jjs-000000030c9-37hF@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox