agora inbox for pgsql-committers@postgresql.org
help / color / mirror / Atom feedFrom: Tom Lane <tgl@sss.pgh.pa.us>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Modernize crypt-des.c a bit, avoiding dubious casts.
Date: Fri, 25 Sep 2026 19:34:54 +0000
Message-ID: <E1xABh8-00000001Fkl-1WhO@gemulon.postgresql.org> (raw)
Modernize crypt-des.c a bit, avoiding dubious casts.
The header comment for this file says it assumes that "the CPU is not
picky about alignment", which we wouldn't really accept for Postgres.
The two functions that have alignment requirements have been hacked in
ways that are inconsistent and yet both ugly. des_setkey just casts
its "const char *" argument to "const uint32 *", relying on the caller
to ensure that that pointer is actually word-aligned, which the caller
does by declaring the buffer as uint32[] and then casting to "char *".
Meanwhile des_cipher carefully memcpy's to and from an internal
uint32[] buffer, which is pretty silly given that what it's passed
must be word-aligned for the benefit of des_setkey. And on top of
that we have a bunch of ugly casting and oddly-written pointer
arithmetic in the caller px_crypt_des. The odd pointer arithmetic
causes warnings about possible buffer overrun when using recent gcc
at -O3 or higher.
Let's clean this up by converting the buffer variable into a union
of a uint8 array and a uint32 array, so that we can remove all these
casts, and also replace the strange loop logic with a simple subscript
variable to satisfy gcc.
Reported-by: Andres Freund <andres@anarazel.de>
Author: Tom Lane <tgl@sss.pgh.pa.us>
Co-authored-by: Ayush Tiwari <ayushtiwari.slg01@gmail.com>
Discussion: https://postgr.es/m/2005885.1790359097@sss.pgh.pa.us
Discussion: https://postgr.es/m/3nuudxv365kjnmwjhnygdakhxuktpdjvf26rt26eb44esgqdrj@y2x3vomkrfoo
Backpatch-through: 14
Branch
------
REL_16_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/901952844bfcd936e961ed7f38ed7c9a8098be48
Modified Files
--------------
contrib/pgcrypto/crypt-des.c | 53 ++++++++++++++++++--------------------------
1 file changed, 21 insertions(+), 32 deletions(-)
view thread (7+ messages) latest in thread
Message-ID: <E1xABh8-00000001Fkl-1WhO@gemulon.postgresql.org>
Permalink: ../E1xABh8-00000001Fkl-1WhO@gemulon.postgresql.org/
Also on: postgresql.org/message-id/E1xABh8-00000001Fkl-1WhO@gemulon.postgresql.org
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-committers@postgresql.org
Cc: tgl@sss.pgh.pa.us, pgsql-committers@lists.postgresql.org
Subject: Re: pgsql: Modernize crypt-des.c a bit, avoiding dubious casts.
In-Reply-To: <E1xABh8-00000001Fkl-1WhO@gemulon.postgresql.org>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox