Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wnM5D-000G0r-1O for pgsql-hackers@arkaria.postgresql.org; Fri, 24 Jul 2026 20:01:23 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wnM5C-004uFf-1P for pgsql-hackers@arkaria.postgresql.org; Fri, 24 Jul 2026 20:01:22 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wnM5C-004uFX-0S for pgsql-hackers@lists.postgresql.org; Fri, 24 Jul 2026 20:01:22 +0000 Received: from mail-ua1-x932.google.com ([2607:f8b0:4864:20::932]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1wnM59-000000005G8-3c1a for pgsql-hackers@lists.postgresql.org; Fri, 24 Jul 2026 20:01:21 +0000 Received: by mail-ua1-x932.google.com with SMTP id a1e0cc1a2514c-9770fffa5a6so262096241.3 for ; Fri, 24 Jul 2026 13:01:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784923278; x=1785528078; darn=lists.postgresql.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:from:to:cc:subject:date:message-id:reply-to:content-type; bh=DqOvzeiShLPnaC/EdhT3kSWwfzUU1uy8NizAe3CxGD4=; b=AxXSgTMSB2J/RRwc/ivs0hjd8ep72KgkPTIC1rSw5UBfEHtAz+/RVqRvNWR8hMppSm lJVY0w7NN393G7D+KXHaqDVm2iZkjeygEBLZgdSaiBg65Y9vDOdjSVG2p3n1F32JkDUd ekuhr4rZ4f/u2aTgsnM9H71ddy+LjHmO5GV1Vmlxn3HWFYuQdZM3KnmTbSf1zIxmVI4G kzdI82USShIHPBuEWwKYCV+XcS//gttDEGglFB5UfdgSilhWollgb4EQ4YWH3GhnDAxf gXVD7xvVYPDwVznhXz1SNeMCHqw5dC+GeTDoC6Arx9FeI9lI3A33dG7zqw304Om8EFc4 hPdg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784923278; x=1785528078; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=DqOvzeiShLPnaC/EdhT3kSWwfzUU1uy8NizAe3CxGD4=; b=ODhtuNUa3/qoASd0EGr50pCdpgw0uvVfrUtjYLdLPNCsuki6QC+Y7vBrZD7VIb1bc6 prddpXzbmZ5I/+KkCdeHZyVz7OgyeGWnoY3yRINwnfRhzf3qff0bgJONH1IayhLdGdPw 8jr4YUBDftLJK+loAK0r0u26J0OlMOO1CJh6va/tICyGu5S6XXCXmPvoNWQFadMZvIwy YVRfGhiUP+hFE+LDK5ikVmqBj+IxlNPagQ0JRna6Lwwh4FnpU7q05WftHdv+/Cl+x1Qf +AlWMRkIU3DegrYPYNEdPs/746q+11gLBA0Oh92yxFCHIgMIhDrgf5bDKZK9uDDDvzHN NFsw== X-Forwarded-Encrypted: i=1; AHgh+RqoT79d19EoIOM8VxBSGPGTACyvuUhYI895br2gTTwXWfwb+AI9u6yxTmA9Q2dVi3E82AsxLtALmfHKU6Uc@lists.postgresql.org X-Gm-Message-State: AOJu0Yx6SEfAzRethMFcY8Wpxetg554EXmpSe5QDsl0EulJi/RnHZCt5 IRSfbTj/zTuotMaUpbt1RWteX3agf6bwnjMpEY2Yr8BSBc4mPyMeLUp8 X-Gm-Gg: AR+sD119P6dTivz2ARfDaDrr78xL3HVf9VZvtA0BXKK36ZaQTEzsex3YL4PsdhU+gBG 1JEIkzYp92Zmet8niftMMnE97dOETyuhSwevmTGxvELS1+TZjNw6i/T+hK6sB8sNJD8EKhx+HnD Gwiy8s7fD8X4/yTgt/7M6YCWnR4C6nj04hkh/EWBDRW4vwquUQgcrC9GWhxqBnWKqZsGIYF6C+p TKxFo8EqXlPzMz6DPNuE6zZvg6NGv08FpsxqG/qzpIL3l4JtM55HtiKfqOILrDfNhcJ0rSBIse7 9Z+RDX9rkDpqTn/ZIsXx4FnqCCTad5FmDaBeMf8UPE1opWBqmlGF2cGLeSw7jYa44PkzfCQ3vbK bNIJYfqDOnGvanpoR5o6doC8NZUn00NsE76h56jlgBo8Ghvdbx+M/fj8nwbyDo5Vv8sBhkVGT6n 0lLSQE/fVvqU/0POHY X-Received: by 2002:a05:6102:570e:b0:739:5f55:3c3c with SMTP id ada2fe7eead31-74d5fed82e4mr4501148137.13.1784923277650; Fri, 24 Jul 2026 13:01:17 -0700 (PDT) Received: from nathan ([50.217.229.234]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-907e85241e7sm5786516d6.8.2026.07.24.13.01.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 24 Jul 2026 13:01:15 -0700 (PDT) Date: Fri, 24 Jul 2026 16:01:13 -0400 From: Nathan Bossart To: =?utf-8?B?0KXQsNC80LjQtNGD0LvQu9C40L0g0KDRg9GB0YLQsNC8?= Cc: Mats Kindahl , Andres Freund , Tom Lane , Thomas Munro , Heikki Linnakangas , pgsql-hackers@lists.postgresql.org Subject: Re: glibc qsort() vulnerability Message-ID: References: <20240212213130.jp5vwotwazypaaez@awork3.anarazel.de> <20240212230423.GA3519@nathanxps13> <20240212234134.ilwrxvwyza3vvps7@awork3.anarazel.de> <20240213181044.GA13935@nathanxps13> <20240215233219.GA1204090@nathanxps13> <20240216200951.GA1511686@nathanxps13> <5c5a7984-b149-b505-7ad9-2a7766c65b55@postgrespro.ru> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <5c5a7984-b149-b505-7ad9-2a7766c65b55@postgrespro.ru> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Fri, Jul 24, 2026 at 06:12:03PM +0300, Хамидуллин Рустам wrote: >  static int  >  db_comparator(const void *a, const void *b)  >  {  > -    if (((const avl_dbase *) a)->adl_score == ((const avl_dbase *) b)->adl_score)  > -        return 0;  > -    else  > -        return (((const avl_dbase *) a)->adl_score < ((const avl_dbase *) b)->adl_score) ? 1 : -1;  > +    return pg_cmp_s32(((const avl_dbase *) a)->adl_score,  > +                      ((const avl_dbase *) b)->adl_score);  >  }  > > It breaks the database vacuuming order. The order should clearly be different here.  > This bug was introduced in PostgreSQL 17. I have attached а fix.  Oops, I think you're right. Thanks for reporting. I'll plan on committing this sometime next week. -- nathan