Commit 3abe6e0
committed
Make escaping functions retain trailing bytes of an invalid character.
Instead of dropping the trailing byte(s) of an invalid or incomplete
multibyte character, replace only the first byte with a known-invalid
sequence, and process the rest normally. This seems less likely to
confuse incautious callers than the behavior adopted in 5dc1e42.
While we're at it, adjust PQescapeStringInternal to produce at most
one bleat about invalid multibyte characters per string. This
matches the behavior of PQescapeInternal, and avoids the risk of
producing tons of repetitive junk if a long string is simply given
in the wrong encoding.
This is a followup to the fixes for CVE-2025-1094, and should be
included if cherry-picking those fixes.
Author: Andres Freund <andres@anarazel.de>
Co-authored-by: Tom Lane <tgl@sss.pgh.pa.us>
Reported-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/20250215012712.45@rfd.leadboat.com
Backpatch-through: 131 parent a92db3d commit 3abe6e0
2 files changed
+65
-95
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
180 | 180 | | |
181 | 181 | | |
182 | 182 | | |
183 | | - | |
184 | | - | |
185 | | - | |
186 | | - | |
187 | | - | |
188 | | - | |
189 | | - | |
190 | | - | |
191 | | - | |
192 | | - | |
193 | | - | |
194 | | - | |
195 | | - | |
196 | | - | |
197 | | - | |
198 | | - | |
199 | | - | |
200 | | - | |
201 | | - | |
| 183 | + | |
| 184 | + | |
202 | 185 | | |
203 | 186 | | |
204 | 187 | | |
205 | | - | |
| 188 | + | |
206 | 189 | | |
207 | 190 | | |
208 | 191 | | |
209 | | - | |
210 | | - | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
211 | 196 | | |
212 | 197 | | |
213 | 198 | | |
214 | | - | |
215 | | - | |
216 | | - | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
217 | 202 | | |
218 | 203 | | |
219 | 204 | | |
| |||
222 | 207 | | |
223 | 208 | | |
224 | 209 | | |
225 | | - | |
226 | | - | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
227 | 214 | | |
228 | | - | |
229 | | - | |
| 215 | + | |
| 216 | + | |
230 | 217 | | |
231 | 218 | | |
232 | 219 | | |
| |||
395 | 382 | | |
396 | 383 | | |
397 | 384 | | |
398 | | - | |
399 | | - | |
400 | | - | |
401 | | - | |
402 | | - | |
403 | | - | |
404 | | - | |
405 | | - | |
406 | | - | |
407 | | - | |
408 | | - | |
409 | | - | |
410 | | - | |
411 | | - | |
412 | | - | |
413 | | - | |
414 | | - | |
415 | | - | |
416 | | - | |
| 385 | + | |
| 386 | + | |
417 | 387 | | |
418 | 388 | | |
419 | 389 | | |
420 | | - | |
| 390 | + | |
421 | 391 | | |
422 | 392 | | |
423 | 393 | | |
424 | | - | |
425 | | - | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
426 | 402 | | |
427 | 403 | | |
428 | 404 | | |
429 | | - | |
430 | | - | |
| 405 | + | |
| 406 | + | |
431 | 407 | | |
432 | 408 | | |
433 | 409 | | |
434 | | - | |
435 | 410 | | |
436 | 411 | | |
437 | | - | |
438 | | - | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
439 | 415 | | |
440 | | - | |
| 416 | + | |
| 417 | + | |
441 | 418 | | |
442 | 419 | | |
443 | 420 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4076 | 4076 | | |
4077 | 4077 | | |
4078 | 4078 | | |
| 4079 | + | |
4079 | 4080 | | |
4080 | 4081 | | |
4081 | 4082 | | |
| |||
4102 | 4103 | | |
4103 | 4104 | | |
4104 | 4105 | | |
4105 | | - | |
| 4106 | + | |
| 4107 | + | |
4106 | 4108 | | |
4107 | 4109 | | |
4108 | | - | |
4109 | | - | |
4110 | | - | |
4111 | | - | |
4112 | | - | |
| 4110 | + | |
| 4111 | + | |
| 4112 | + | |
| 4113 | + | |
| 4114 | + | |
| 4115 | + | |
| 4116 | + | |
| 4117 | + | |
| 4118 | + | |
4113 | 4119 | | |
4114 | 4120 | | |
4115 | | - | |
4116 | | - | |
| 4121 | + | |
| 4122 | + | |
| 4123 | + | |
4117 | 4124 | | |
4118 | 4125 | | |
4119 | 4126 | | |
4120 | 4127 | | |
4121 | 4128 | | |
4122 | | - | |
4123 | | - | |
4124 | | - | |
4125 | | - | |
4126 | | - | |
4127 | | - | |
4128 | | - | |
4129 | | - | |
4130 | | - | |
4131 | | - | |
4132 | | - | |
4133 | | - | |
4134 | | - | |
4135 | | - | |
4136 | | - | |
4137 | | - | |
4138 | | - | |
4139 | | - | |
4140 | | - | |
4141 | | - | |
4142 | | - | |
4143 | | - | |
4144 | 4129 | | |
4145 | 4130 | | |
4146 | 4131 | | |
4147 | | - | |
4148 | | - | |
| 4132 | + | |
| 4133 | + | |
4149 | 4134 | | |
4150 | 4135 | | |
4151 | 4136 | | |
4152 | | - | |
4153 | | - | |
| 4137 | + | |
| 4138 | + | |
| 4139 | + | |
| 4140 | + | |
| 4141 | + | |
| 4142 | + | |
| 4143 | + | |
| 4144 | + | |
| 4145 | + | |
4154 | 4146 | | |
4155 | 4147 | | |
4156 | 4148 | | |
4157 | | - | |
4158 | 4149 | | |
4159 | 4150 | | |
4160 | | - | |
4161 | | - | |
| 4151 | + | |
| 4152 | + | |
| 4153 | + | |
4162 | 4154 | | |
4163 | | - | |
| 4155 | + | |
| 4156 | + | |
4164 | 4157 | | |
4165 | 4158 | | |
4166 | 4159 | | |
| |||
0 commit comments