Clamp hstore text parser pair-count estimate - #2643
Open
AshSgDe29071999 wants to merge 1 commit into
Open
Conversation
parseHstore sized the result map from the number of '>' bytes in untrusted input before any pair was validated. A value of only '>' reserved memory proportional to its length and then failed immediately. Capacity is only a hint, so clamping cannot change accepted inputs. See jackc#2639
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2639
parseHstoresized both the value-string slice and the result map fromstrings.Count(s, ">")before any pair was parsed. A value consisting only of>reserved memory proportional to its length and then failed on the firstconsumeExpectedByte('"').That path is reachable from wire data (
scanPlanTextAnyToHstoreScanner→parseHstore). Capacity is only a hint toappendandmake(map), so clamping the estimate cannot change which inputs are accepted or what a successful parse returns.The garbage-input test covers the unvalidated count. The 2000-pair test checks that a legitimate hstore larger than the clamp still parses completely.