pgsql: Fix handling of R/W expanded datums that are passed to SQL funct

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Fix handling of R/W expanded datums that are passed to SQL funct
Date: 2022-08-10 17:37:47
Message-ID: E1oLpeM-0009ey-Mm@gemulon.postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Fix handling of R/W expanded datums that are passed to SQL functions.

fmgr_sql must make expanded-datum arguments read-only, because
it's possible that the function body will pass the argument to
more than one callee function. If one of those functions takes
the datum's R/W property as license to scribble on it, then later
callees will see an unexpected value, leading to wrong answers.

From a performance standpoint, it'd be nice to skip this in the
common case that the argument value is passed to only one callee.
However, detecting that seems fairly hard, and certainly not
something that I care to attempt in a back-patched bug fix.

Per report from Adam Mackler. This has been broken since we
invented expanded datums, so back-patch to all supported branches.

Discussion: https://postgr.es/m/WScDU5qfoZ7PB2gXwNqwGGgDPmWzz08VdydcPFLhOwUKZcdWbblbo-0Lku-qhuEiZoXJ82jpiQU4hOjOcrevYEDeoAvz6nR0IU4IHhXnaCA=@mackler.email
Discussion: https://postgr.es/m/187436.1660143060@sss.pgh.pa.us

Branch
------
REL_11_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/442dbd6698282faafc0b83363cecf818cf88a9b6

Modified Files
--------------
src/backend/executor/functions.c | 19 +++++++++++++++++--
src/test/regress/expected/create_function_3.out | 18 +++++++++++++++++-
src/test/regress/sql/create_function_3.sql | 13 +++++++++++++
3 files changed, 47 insertions(+), 3 deletions(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Tom Lane 2022-08-10 17:37:48 pgsql: Fix handling of R/W expanded datums that are passed to SQL funct
Previous Message Alvaro Herrera 2022-08-10 14:03:34 Re: pgsql: Rely on __func__ being supported