agora inbox for pgsql-hackers@postgresql.org  
help / color / mirror / Atom feed
From: Nathan Bossart <nathandbossart@gmail.com>
To: Andres Freund <andres@anarazel.de>
Cc: Mats Kindahl <mats@timescale.com>
Cc: Tom Lane <tgl@sss.pgh.pa.us>
Cc: Thomas Munro <thomas.munro@gmail.com>
Cc: Heikki Linnakangas <hlinnaka@iki.fi>
Cc: pgsql-hackers@lists.postgresql.org
Subject: Re: glibc qsort() vulnerability
Date: Mon, 12 Feb 2024 17:04:23 -0600
Message-ID: <20240212230423.GA3519@nathanxps13> (raw)
In-Reply-To: <20240212213130.jp5vwotwazypaaez@awork3.anarazel.de>
References: <CA+14427pVjvgnVGiyM45e_EyKgCmzgRiK3dSQJqfOtHAnY8Maw@mail.gmail.com>
	<CA+14427QfHELBNskJKPHA96yOJ6aUZE_XqbFBC7hz+hmywTtPQ@mail.gmail.com>
	<20240209200828.GB665650@nathanxps13>
	<CA+14425kn0RxC62M7ZaD5BRzBJEPRRLQQB4DGdL+=vxHS1E81Q@mail.gmail.com>
	<20240210205332.GA1124797@nathanxps13>
	<CA+14427j_ExhaicH96i3k8OnZaHYkYQtPm-Q66BzY96W3qBJ-A@mail.gmail.com>
	<20240212155715.GB1645880@nathanxps13>
	<CA+14426fK=NNECQDo7cmRHi5CfhRQcUqprfrzhat9MK2dYXK+A@mail.gmail.com>
	<20240212205138.GA1815383@nathanxps13>
	<20240212213130.jp5vwotwazypaaez@awork3.anarazel.de>

On Mon, Feb 12, 2024 at 01:31:30PM -0800, Andres Freund wrote:
> One thing that's worth checking is if this ends up with *worse* code when the
> comparators are inlined. I think none of the changed comparators will end up
> getting used with an inlined sort, but ...

Yeah, AFAICT the only inlined sorts are in tuplesort.c and bufmgr.c, and
the patches don't touch those files.

> The reason we could end up with worse code is that when inlining the
> comparisons would make less sense for the compiler. Consider e.g.
> 	return DO_COMPARE(a, b) < 0 ?
> 		(DO_COMPARE(b, c) < 0 ? b : (DO_COMPARE(a, c) < 0 ? c : a))
> 		: (DO_COMPARE(b, c) > 0 ? b : (DO_COMPARE(a, c) < 0 ? a : c));
> 
> With a naive implementation the compiler will understand it only cares about
> a < b, not about the other possibilities. I'm not sure that's still true with
> the more complicated optimized version.

You aren't kidding [0].  Besides perhaps adding a comment in
sort_template.h, is there anything else you think we should do about this
now?

[0] https://godbolt.org/z/bbTqK54zK

-- 
Nathan Bossart
Amazon Web Services: https://aws.amazon.com





view thread (64+ messages)  latest in thread

Message-ID: <20240212230423.GA3519@nathanxps13>
Permalink:  ../20240212230423.GA3519@nathanxps13/
Also on:    postgresql.org/message-id/20240212230423.GA3519@nathanxps13

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-hackers@postgresql.org
  Cc: nathandbossart@gmail.com, andres@anarazel.de, mats@timescale.com, tgl@sss.pgh.pa.us, thomas.munro@gmail.com, hlinnaka@iki.fi, pgsql-hackers@lists.postgresql.org
  Subject: Re: glibc qsort() vulnerability
  In-Reply-To: <20240212230423.GA3519@nathanxps13>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox