Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1rYAgU-00EiKk-3Y for pgsql-hackers@arkaria.postgresql.org; Thu, 08 Feb 2024 20:07:46 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1rYAgT-002ap4-5t for pgsql-hackers@arkaria.postgresql.org; Thu, 08 Feb 2024 20:07:45 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1rYAgS-002aow-Sj for pgsql-hackers@lists.postgresql.org; Thu, 08 Feb 2024 20:07:44 +0000 Received: from mail-io1-xd2d.google.com ([2607:f8b0:4864:20::d2d]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1rYAgQ-005lfk-6z for pgsql-hackers@lists.postgresql.org; Thu, 08 Feb 2024 20:07:43 +0000 Received: by mail-io1-xd2d.google.com with SMTP id ca18e2360f4ac-7bffface817so5558439f.3 for ; Thu, 08 Feb 2024 12:07:42 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1707422861; x=1708027661; darn=lists.postgresql.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=GbOMvmBBg0olBnKP6c3iECBYZAp+efSLtqmLi/PTl8Q=; b=GIiqdX2rOHKVX6oHN2/c5jLKBX7JnERf4nH/E/3s9r9RfH7w/ve/EUh98dOXZ1tZTd qD7VZkrBs/AYSEP81l3gk5ifDCt3fjSvBowGtVK6DCIQcStboy4XtyWNvqJjb/BsWAbS SlqJ5eIl7/Xxw9nufRWjFAyREpR6z1oMgiYkOujpGmNTi9q/3rGWb2y4NlW+DFEpFNjM iqACapfn3yL+CKMtIN+LkGlWXIENbcexrUFrPbYFnusmaqHdZdeOgROTXTI3YlKlT5AK UB/B09286wK0aReNj0ZC7fa0sPljsrrPPG0b7AJxFTNzFSIcG/PSj4MfNgchNtRMPJEy bZSA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1707422861; x=1708027661; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=GbOMvmBBg0olBnKP6c3iECBYZAp+efSLtqmLi/PTl8Q=; b=eEos5nemOaGNSdAH0HKPbKcXmj5gmCoRRjl3JNfrkGWAJ6GWIyIOeycT9GuqWaivLG UyVvZZeAs1fepMP441wOnngHNXxxkvWzmIwQrGXY34MURMqGHWlL9Q4JCX3nO4djULdD e0CXBkssz7N+lxEYEd/ZpK5RK+uEc821yAWpIa5M3FR7p/N7P8X/2J1xwJoM4p/R7JQo ++DeNwrc3tavFP6VEPN0kcMmgZWS78jfyGWBaSmGd2nqzB6B6zfqsPK23nidzIeZnJ7v Hph9ouvl04tBJlGLCuHlZGZCK5sfaj8MwUCn7rNcRpsX11vhFxjZkOkslllJFgkjoZ5y zFBg== X-Forwarded-Encrypted: i=1; AJvYcCUs75Ymiff2AcQ+SUxSuvg3kejmleSr9aq11aO7NvA6G8nR6kqbsFwiR3lBigeRQ7Q8aMmQmvr8pq4TX6ccSLiSWWuknLgXAv0B6Qr294PbPhRl X-Gm-Message-State: AOJu0YwJgzZ19rihTNApAZLt9NCC9UzbUTKi5KmWuz829tl9ez7RpnHk 5DMdA4P6mmzjQPeAtre4AV/bLqrC04zFcsvoBpyXIDGts7TMcTto X-Google-Smtp-Source: AGHT+IH7btuQjQQ863ziac976+MAWzq4mABSmmcjZRrO2LsL7ba9JGKo2GY+AdYww3ZoCPLT35586Q== X-Received: by 2002:a5e:8603:0:b0:7c4:2fc9:58c4 with SMTP id z3-20020a5e8603000000b007c42fc958c4mr398810ioj.7.1707422861402; Thu, 08 Feb 2024 12:07:41 -0800 (PST) X-Forwarded-Encrypted: i=1; AJvYcCV4pOqV4DHczd7N4S/DK/dIv0vdCjZj6MoFJOcx+LkW4DpUE/HuWJZBG8rOc0xqF7s5F25D52juYcku1TXbEj3t/bQ8NEzgxBpCMPi9FLKFGoG6Kwcrt8DCx3XmRMgjmqkX5OU602kZ7bhtZQJoIElUdomlfTtK2lsDgglFroLZslrR5Pd6W3+B51yaDwsr6Q== Received: from nathanxps13 (162-195-168-172.lightspeed.stlsmo.sbcglobal.net. [162.195.168.172]) by smtp.gmail.com with ESMTPSA id br18-20020a05663846d200b00470b42dfc1csm26956jab.63.2024.02.08.12.07.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 08 Feb 2024 12:07:41 -0800 (PST) Date: Thu, 8 Feb 2024 14:07:37 -0600 From: Nathan Bossart To: Andres Freund Cc: Tom Lane , Mats Kindahl , Thomas Munro , Heikki Linnakangas , pgsql-hackers@lists.postgresql.org Subject: Re: glibc qsort() vulnerability Message-ID: <20240208200737.GA504276@nathanxps13> References: <20240208004207.aoyrtv577nmhrivy@awork3.anarazel.de> <20240208015211.GA445153@nathanxps13> <20240208020637.3irwi5vph4fbxw2f@awork3.anarazel.de> <20240208025620.GC445153@nathanxps13> <20240208183835.GA503311@nathanxps13> <1074897.1707417842@sss.pgh.pa.us> <20240208195954.vlpoii4ftoow2of4@awork3.anarazel.de> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20240208195954.vlpoii4ftoow2of4@awork3.anarazel.de> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Thu, Feb 08, 2024 at 11:59:54AM -0800, Andres Freund wrote: > On 2024-02-08 13:44:02 -0500, Tom Lane wrote: >> Are we okay with using macros that (a) have double evaluation hazards >> and (b) don't enforce the data types being compared are the same? >> I think static inlines might be a safer technology. > > +1 Agreed on static inlines. > I'd put these static inlines into common/int.h. I don't think this is common > enough to warrant being in c.h. Probably also doesn't hurt to have a not quite > as generic name as INT_CMP, I'd not be too surprised if that's defined in some > library. > > > I think it's worth following int.h's pattern of including [s]igned/[u]nsigned > in the name, an efficient implementation for signed might not be the same as > for unsigned. And if we use static inlines, we need to do so for correct > semantics anyway. Seems reasonable to me. -- Nathan Bossart Amazon Web Services: https://aws.amazon.com