agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
From: Daniel Gustafsson <dgustafsson@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Fix right() with the most negative integer
Date: Tue, 01 Sep 2026 08:21:17 +0000
Message-ID: <E1x1Jk4-000000030cn-33Ka@gemulon.postgresql.org> (raw)

Fix right() with the most negative integer

A negative n means "return all but the first |n| characters", so
text_right() negates n before clipping.  Negating PG_INT32_MIN overflows;
with -fwrapv the result is PG_INT32_MIN again, still negative, and
pg_mbcharcliplen() then returns an offset of zero, so the whole string is
returned where the correct answer is an empty string:

    SELECT right('abcdef', (-2147483648)::int4);   -- 'abcdef', want ''
    SELECT right('abcdef', -2147483647);           -- '', correct

Clamp to PG_INT32_MAX instead.  Any n whose absolute value is at least the
string's length skips all of it, and a text value cannot be longer than
PG_INT32_MAX, so this gives the same answer for every other input.  Note
that erroring out, as text_format_string_conversion() does for a width of
INT_MIN a few hundred lines away, would not be right here: unlike a format
width, an out-of-range skip count has a well-defined result.

text_left() is not affected.  Its negative case computes the character
length plus n rather than negating n, and since the length is non-negative
and bounded by the varlena size limit that sum cannot overflow.

Backpatch to all supported versions.

Author: Ewan Young <kdbase.hack@gmail.com>
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
Reviewed-by: Dagfinn Ilmari Mannsåker <ilmari@ilmari.org>
Reviewed-by: David Rowley <dgrowleyml@gmail.com>
Reviewed-by: Chao Li <li.evan.chao@gmail.com>
Discussion: https://postgr.es/m/CAON2xHNnBz-AcPJgDmd5_39+8qR5AUKEZk4X3ZM-0zdsATn8kQ@mail.gmail.com
Backpatch-through: 14

Branch
------
REL_15_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/729bac9eb1042a722f21c6f6dfb5d0f6b0e6c67a

Modified Files
--------------
src/backend/utils/adt/varlena.c    | 12 +++++++++++-
src/test/regress/expected/text.out |  8 ++++++++
src/test/regress/sql/text.sql      |  3 +++
3 files changed, 22 insertions(+), 1 deletion(-)



Message-ID: <E1x1Jk4-000000030cn-33Ka@gemulon.postgresql.org>
Permalink:  ../E1x1Jk4-000000030cn-33Ka@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1x1Jk4-000000030cn-33Ka@gemulon.postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: dgustafsson@postgresql.org, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Fix right() with the most negative integer
  In-Reply-To: <E1x1Jk4-000000030cn-33Ka@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox