postgresql/contrib/intarray
Andrew Gierth 5f11a500fa Avoid crashes in contrib/intarray gist__int_ops (bug #15518)
1. Integer overflow in internal_size could result in memory corruption
in decompression since a zero-length array would be allocated and then
written to. This leads to crashes or corruption when traversing an
index which has been populated with sufficiently sparse values. Fix by
using int64 for computations and checking for overflow.

2. Integer overflow in g_int_compress could cause pessimal merge
choices, resulting in unnecessarily large ranges (which would in turn
trigger issue 1 above). Fix by using int64 again.

3. Even without overflow, array sizes could become large enough to
cause unexplained memory allocation errors. Fix by capping the sizes
to a safe limit and report actual errors pointing at gist__intbig_ops
as needed.

4. Large inputs to the compression function always consist of large
runs of consecutive integers, and the compression loop was processing
these one at a time in an O(N^2) manner with a lot of overhead. The
expected runtime of this function could easily exceed 6 months for a
single call as a result. Fix by performing a linear-time first pass,
which reduces the worst case to something on the order of seconds.

Backpatch all the way, since this has been wrong forever.

Per bug #15518 from report from irc user "dymk", analysis and patch by
me.

Discussion: https://postgr.es/m/15518-799e426c3b4f8358@postgresql.org
2018-11-24 08:39:55 +00:00
..
bench Fix -e option in contrib/intarray/bench/bench.pl. 2016-08-17 15:51:10 -04:00
data 1. Fixed error with empty array ( '{}' ), 2001-08-04 19:35:32 +00:00
expected Add selectivity estimation functions for intarray operators. 2015-07-21 20:59:24 +03:00
sql Add selectivity estimation functions for intarray operators. 2015-07-21 20:59:24 +03:00
_int_bool.c Prevent stack overflow in query-type functions. 2015-10-05 10:06:30 -04:00
_int_gin.c Move strategy numbers to include/access/stratnum.h 2015-05-15 17:03:16 -03:00
_int_gist.c Avoid crashes in contrib/intarray gist__int_ops (bug #15518) 2018-11-24 08:39:55 +00:00
_int_op.c Adjust blank lines around PG_MODULE_MAGIC defines, for consistency 2014-07-10 14:02:08 -04:00
_int_selfuncs.c Update copyright for 2016 2016-01-02 13:33:40 -05:00
_int_tool.c Avoid crashes in contrib/intarray gist__int_ops (bug #15518) 2018-11-24 08:39:55 +00:00
_int.h Use FLEXIBLE_ARRAY_MEMBER in a bunch more places. 2015-02-20 00:11:42 -05:00
_intbig_gist.c Move strategy numbers to include/access/stratnum.h 2015-05-15 17:03:16 -03:00
.gitignore Support "make check" in contrib 2011-04-25 22:27:11 +03:00
intarray--1.0--1.1.sql Add selectivity estimation functions for intarray operators. 2015-07-21 20:59:24 +03:00
intarray--1.1--1.2.sql Update extensions with GIN/GIST support for parallel query. 2016-06-14 13:34:37 -04:00
intarray--1.2.sql Update extensions with GIN/GIST support for parallel query. 2016-06-14 13:34:37 -04:00
intarray--unpackaged--1.0.sql Fix typos in some error messages thrown by extension scripts when fed to psql. 2014-08-25 18:30:37 +02:00
intarray.control Handle contrib's GIN/GIST support function signature changes honestly. 2016-06-09 16:44:25 -04:00
Makefile Handle contrib's GIN/GIST support function signature changes honestly. 2016-06-09 16:44:25 -04:00