agora inbox for pgsql-interfaces@postgresql.org  
help / color / mirror / Atom feed
From: Florian Weimer <fw@deneb.enyo.de>
To: Jeff Davis <pgsql@j-davis.com>
Cc: Karthik Segpi <karthik.segpi@gmail.com>
Cc: pgsql-interfaces@postgresql.org
Subject: Re: PQunescapebytea not reverse of PQescapebytea?
Date: Sun, 18 Sep 2016 16:02:32 +0200
Message-ID: <878tup1f2f.fsf@mid.deneb.enyo.de> (raw)
In-Reply-To: <1395807598.2224.11.camel@jdavis>
References: <CACD7L9GCLsM=wEwwH707sN19dMkMHwHh+ffVmLQdsFXNR0UJ6Q@mail.gmail.com>
	<87bnx20w88.fsf@mid.deneb.enyo.de>
	<1395807598.2224.11.camel@jdavis>
List-Unsubscribe:  <mailto:majordomo@postgresql.org?body=unsub%20pgsql-interfaces>

* Jeff Davis:

> On Wed, 2014-03-19 at 21:28 +0100, Florian Weimer wrote:
>> * Karthik Segpi:
>> 
>> > I have a 'bytea' column in the database, onto which my custom C application
>> > is inserting encrypted data. Before inserting, I am calling
>> > 'PQescapebytea()' to escape the ciphertext. However, after SELECT, the data
>> > needs to be 'un-escaped' before attempting to decrypt. I am trying to
>> > 'un-escape' using 'PQunescapebytea'. However, I am finding that
>> > 'PQunescapebytea' is not  exact inverse of 'PQescapebytea'. I saw
>> > documentation and posts in the mailing lists alluding to this as well. As a
>> > result, the decryption always fails.
>> 
>> Can you show us some example data that shows the inconsistency?
>> PQunescapebytea should give you back the blob you passed to
>> PQescapebytea, but the same blob can have different BYTEA
>> encodings—not everyone uses the \x hexadecimal encoding.
>
> Example:
>
>   size_t len1, len2;
>   char *str = "\\\\123";
>
>   printf("%s\n", str);
>   printf("%s\n", PQescapeBytea(str, strlen(str), &len1));
>   printf("%s\n", PQunescapeBytea(
>                                  PQescapeBytea(str, strlen(str), &len1),
>                                  &len2));
>
> The reason for this is that PQescapeBytea is designed to escape it to be
> passed into the server via a SQL string (adding two levels of escaping,
> one for the sql string and one for bytea); whereas PQunescapeBytea is
> designed to unescape a result coming back from the server (which only
> has one level of escaping to undo: the bytea escaping).

Ah, right, this is annoying.  I think a thin (one-level) escaping
function would make sense to add to libpq.


-- 
Sent via pgsql-interfaces mailing list (pgsql-interfaces@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-interfaces



view thread (4+ messages)

Message-ID: <878tup1f2f.fsf@mid.deneb.enyo.de>
Permalink:  ../878tup1f2f.fsf@mid.deneb.enyo.de/
Also on:    postgresql.org/message-id/878tup1f2f.fsf@mid.deneb.enyo.de

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-interfaces@postgresql.org
  Cc: fw@deneb.enyo.de, pgsql@j-davis.com, karthik.segpi@gmail.com
  Subject: Re: PQunescapebytea not reverse of PQescapebytea?
  In-Reply-To: <878tup1f2f.fsf@mid.deneb.enyo.de>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox