Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1rZfLo-005kql-Nu for pgsql-hackers@arkaria.postgresql.org; Mon, 12 Feb 2024 23:04:37 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1rZfLn-00E5Zm-RN for pgsql-hackers@arkaria.postgresql.org; Mon, 12 Feb 2024 23:04:35 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1rZfLn-00E5Zd-Fg for pgsql-hackers@lists.postgresql.org; Mon, 12 Feb 2024 23:04:35 +0000 Received: from mail-io1-xd2b.google.com ([2607:f8b0:4864:20::d2b]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1rZfLf-006szW-Nu for pgsql-hackers@lists.postgresql.org; Mon, 12 Feb 2024 23:04:34 +0000 Received: by mail-io1-xd2b.google.com with SMTP id ca18e2360f4ac-7bf0f3bf331so158059239f.3 for ; Mon, 12 Feb 2024 15:04:27 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1707779065; x=1708383865; darn=lists.postgresql.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=Jsjp5RjCsCKIPN19pe5m6H0EKlxSb9FEet7kGEj4+OY=; b=eu/K5OghfVjaFoME1To2erdhKI9OEjgiMeByS0u9W0fFNcy2Sl2SMw7p1KKHZQCdRn QJS6wGWpfFOqWu9Ibc4a77WR8HAkou0WOjtUP7fE/lVL4//XdtNpWnKBgzjSoY0B4Lah xQizD49T2Znb7OQYqrt9I+Gxf8mdey+ap9IsOmiCwLkEk61wNFf5qPkxtvruu9Ohpca3 PmBM5HrFNDIU1ZXlQPmuGaXZwlKVSnaiu4kdPft0dcwDvxjSBLEszWZTPxle2acF/J/c QKVr6aVCBp2KY9riqZr4DQQh3PuQErZZJqR/mWLnS9Y0VhIiv41P7mg37gTiVk4dMsvx 3Klw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1707779065; x=1708383865; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=Jsjp5RjCsCKIPN19pe5m6H0EKlxSb9FEet7kGEj4+OY=; b=Gas7OR6qsWVbq1XDmWVUPl288wI9aEGVFHkY33BgTCshKI28E5KMXpYymPR0JQAnVw BA/nti4vIroSCtg/Wi6r5V0pSt8jjPwPYjFON7Sopw+AqCufwRL08vOzUiMTN2/jjijE SfuTqv/h5J2CULayb65xyNmZNS3AW//9LL8D5ANotsifOHj23ocZe3PJsL+Igfeg3D5X Q5IM1GEVF61PIvRqDKwss6vI5+GH3dE4JxdvJdXRY/H/MmUDNYmiCLdYtFXY29dFxcnI 8XIlzidvhq9mF6wNKPro457TyVHwLVAFbhvPrtyxkWyzIokkOoyvcVQgCmQLKTeIWSaj 2/bA== X-Forwarded-Encrypted: i=1; AJvYcCW53xPKFi/SODsLhRZRNn53krYE6QbJU4Ly7Lm+3XrLNYtucAL+S2nJ2UQ8ZntjGcggN6LeEIVwRl3+NJFe713SL5ZIlC3PAyBkfAMgNkcPToQq X-Gm-Message-State: AOJu0Yy0XMOt86a7dAjlQsARu+7MHeqNX62ZYEMMeo4QpBFa77W0KQEo yZS4qoYh1hUFXFYCexcooa+RlQCFUmXgFa2AV4gftAJKrtFppYcj X-Google-Smtp-Source: AGHT+IGIeCcB8hxKO5YZBjDJxLO0hlRctZg8fK/tFu+YbQJx0y/ytNQhrsM/BUP4MrRdgQQkr8OUbA== X-Received: by 2002:a05:6602:2c90:b0:7c4:602a:10a0 with SMTP id i16-20020a0566022c9000b007c4602a10a0mr6963129iow.18.1707779065048; Mon, 12 Feb 2024 15:04:25 -0800 (PST) X-Forwarded-Encrypted: i=1; AJvYcCWJuNS9It1GIC01MmZoFU5SbBdMz/IIilZzXFgcWn6Pn7dm68GOsTAAIW3ULcb1fgef+dPtX0r4FaZnahRNUboHL0LT1XKuM444MMn6HJKt5C3oTKRDoKlrk0EUcDcnqOWdXf9oFJLXUOnjjvnqZCrCKODzsItfjV1bgAO21zXnw0s2s7nsbTLd+1+Nj0iI Received: from nathanxps13 (162-195-168-172.lightspeed.stlsmo.sbcglobal.net. [162.195.168.172]) by smtp.gmail.com with ESMTPSA id 17-20020a5d9c11000000b007c41e541b8fsm1730155ioe.32.2024.02.12.15.04.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 12 Feb 2024 15:04:24 -0800 (PST) Date: Mon, 12 Feb 2024 17:04:23 -0600 From: Nathan Bossart To: Andres Freund Cc: Mats Kindahl , Tom Lane , Thomas Munro , Heikki Linnakangas , pgsql-hackers@lists.postgresql.org Subject: Re: glibc qsort() vulnerability Message-ID: <20240212230423.GA3519@nathanxps13> References: <20240209200828.GB665650@nathanxps13> <20240210205332.GA1124797@nathanxps13> <20240212155715.GB1645880@nathanxps13> <20240212205138.GA1815383@nathanxps13> <20240212213130.jp5vwotwazypaaez@awork3.anarazel.de> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20240212213130.jp5vwotwazypaaez@awork3.anarazel.de> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Mon, Feb 12, 2024 at 01:31:30PM -0800, Andres Freund wrote: > One thing that's worth checking is if this ends up with *worse* code when the > comparators are inlined. I think none of the changed comparators will end up > getting used with an inlined sort, but ... Yeah, AFAICT the only inlined sorts are in tuplesort.c and bufmgr.c, and the patches don't touch those files. > The reason we could end up with worse code is that when inlining the > comparisons would make less sense for the compiler. Consider e.g. > return DO_COMPARE(a, b) < 0 ? > (DO_COMPARE(b, c) < 0 ? b : (DO_COMPARE(a, c) < 0 ? c : a)) > : (DO_COMPARE(b, c) > 0 ? b : (DO_COMPARE(a, c) < 0 ? a : c)); > > With a naive implementation the compiler will understand it only cares about > a < b, not about the other possibilities. I'm not sure that's still true with > the more complicated optimized version. You aren't kidding [0]. Besides perhaps adding a comment in sort_template.h, is there anything else you think we should do about this now? [0] https://godbolt.org/z/bbTqK54zK -- Nathan Bossart Amazon Web Services: https://aws.amazon.com