Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1rYuM7-000nXj-EU for pgsql-hackers@arkaria.postgresql.org; Sat, 10 Feb 2024 20:53:47 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1rYuM4-00HT9F-Gb for pgsql-hackers@arkaria.postgresql.org; Sat, 10 Feb 2024 20:53:44 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1rYuM4-00HT96-4E for pgsql-hackers@lists.postgresql.org; Sat, 10 Feb 2024 20:53:44 +0000 Received: from mail-io1-xd2a.google.com ([2607:f8b0:4864:20::d2a]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1rYuLx-006XHE-Cw for pgsql-hackers@lists.postgresql.org; Sat, 10 Feb 2024 20:53:42 +0000 Received: by mail-io1-xd2a.google.com with SMTP id ca18e2360f4ac-7c00128de31so80191339f.3 for ; Sat, 10 Feb 2024 12:53:36 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1707598415; x=1708203215; darn=lists.postgresql.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=8FLhjpptQcVRE8DoGTTlnuzdjfZduX4AWGP6/IMZK4s=; b=OLq5N8eSeJcqjk1u3PyKKjgV6Vd40pzGfr4Nwu/KtUDjAvmukbHPIRWiG8rTpArTIq rgjy0NZYMFkNt7a7yF/tjYD4ykX6i6sCAY39ASmxwz8v6YoA+Bsupvdp3lGicVZ7ObXX aodpdRB0wTwr0kbKas0nhmhrMGnHGWYhPS5flMCKWYy8fxyCCRnWGhVgSUW6pUsltvdH PjqIKiYffUMzJV7gQVWmZi0t/dwDr6nrvGC0Wy8+wuB9dkFl0rq5CfVwVRlay4vxsf6s 1dwKjX2MBwHXHgsWD9oKblMFlXAFe824S/7nqxBI3p2I9P0rOB3Odqzu0t6oQdp2YVGN NhEQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1707598415; x=1708203215; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=8FLhjpptQcVRE8DoGTTlnuzdjfZduX4AWGP6/IMZK4s=; b=dxvyckb++/M6Mz/caL4MUlQm+WC0PzRw1oZjI68dq5jCbFUvloaVPOqkMzepKWY4Cq k92B6iGoBiLYAuigjhZg6dCn+HRdRAB/ohWLtC+ITawtDzB2QbX+e4HyJhU3EAd766hl JUMVZEkhxRL3PMhPqT3Ug15v9pts/7YW3XvH8h7u59I3r7XxAaCr1BYUbkjvCqt73xwq czJqTVE2jjhzAXwJD9rn1L+q2Yz2xJEOJCuRk8dEI1YurEnJzMtxRMGWtrkkKV4saVGu NJGtOenhxpeH1IyvF437qJSJSWGmOwlPgLuVCvyh3tHbRakn11v1h69PyQ2r1hGZvSZX OLQg== X-Forwarded-Encrypted: i=1; AJvYcCUcJnK8kVxuCIVDhLxgCnuZ8yapEHLxnuVHfbf8wIJqifhMfRdvIqejQ3X01df1e//oc9ByGsFPOlSCUE90qoc899X7IAFjweEokP9X4+/W2Ytc X-Gm-Message-State: AOJu0YzlYt8kItbV2DVZQqxFp7v21bXO6fmkfIjE9Nr1/pa2qQ3Y2LvW 0n8nw1nXOgjhDP7p1kWdb6rl1VYFuRwT7q9Nu4aI2CTGlKXHb9ld X-Google-Smtp-Source: AGHT+IEg/mwDP5u5n3+Lheuw/cRYD/X1OxPSgEjC/E217J+PrLhYvzvZYQI9dW1cYi+Fx17c2G9AnA== X-Received: by 2002:a05:6602:730:b0:7c3:ec69:48e8 with SMTP id g16-20020a056602073000b007c3ec6948e8mr4113354iox.3.1707598414874; Sat, 10 Feb 2024 12:53:34 -0800 (PST) X-Forwarded-Encrypted: i=1; AJvYcCWbpN5VRWFs0KUc0n6ptgK0u6KUzGoDFv1bsUlGTttJQq4PFE3IhMFPQosBuGI+mD4EnCLHQ2crXasfhPlXenEZKDO4JBkAw7D6jGXZwUyqUtm+Ofi/UE0KlmEQXQaqmfOOKisixlYW2sUFqofBFdBbTiO616H+5x304N7+zm8oDhgeEYQMG20rjZE450VmGQ== Received: from nathanxps13 (162-195-168-172.lightspeed.stlsmo.sbcglobal.net. [162.195.168.172]) by smtp.gmail.com with ESMTPSA id l3-20020a02cce3000000b004710245b94bsm551226jaq.59.2024.02.10.12.53.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 10 Feb 2024 12:53:34 -0800 (PST) Date: Sat, 10 Feb 2024 14:53:32 -0600 From: Nathan Bossart To: Mats Kindahl Cc: Tom Lane , Andres Freund , Thomas Munro , Heikki Linnakangas , pgsql-hackers@lists.postgresql.org Subject: Re: glibc qsort() vulnerability Message-ID: <20240210205332.GA1124797@nathanxps13> References: <1074897.1707417842@sss.pgh.pa.us> <20240208195954.vlpoii4ftoow2of4@awork3.anarazel.de> <20240208200737.GA504276@nathanxps13> <1242426.1707424769@sss.pgh.pa.us> <20240209162433.GA663211@nathanxps13> <20240209200828.GB665650@nathanxps13> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Sat, Feb 10, 2024 at 08:59:06AM +0100, Mats Kindahl wrote: > Split the code into two patches: one that just adds the functions > (including the new pg_cmp_size()) to common/int.h and one that starts using > them. I picked the name "pg_cmp_size" rather than "pg_cmp_size_t" since > "_t" is usually used as a suffix for types. > > I added a comment to the (a > b) - (a < b) return and have also added casts > to (int32) for the int16 and uint16 functions (we need a signed int for > uin16 since we need to be able to get a negative number). > > Changed the type of two instances that had an implicit cast from size_t to > int and used the new pg_,cmp_size() function. > > Also fixed the missed replacements in the "contrib" directory. Thanks for the new patches. I think the comparison in resowner.c is backwards, and I think we should expand on some of the commentary in int.h. For example, the comment at the top of int.h seems very tailored to the existing functions and should probably be adjusted. And the "comparison routines for integers" comment might benefit from some additional details about the purpose and guarantees of the new functions. -- Nathan Bossart Amazon Web Services: https://aws.amazon.com