- Security fix: Heap out-of-bounds write and read in pg_query_normalize (GHSA-6ggm-xmc9-8ffg)
- When normalizing certain utility statements (e.g.
DO ... LANGUAGE, statements with
string options, orCREATE/ALTER SUBSCRIPTION ... CONNECTION), pg_query_normalize
searched the query text for the location of string constants, which could yield
wrong locations for crafted input. This could cause out-of-bounds writes and reads
on the heap, leaking process memory in the normalized output or crashing the process. - Constant locations are now recorded by the parser instead, and the normalizer checks
at runtime that constant locations never overlap - This adds new location fields to the parse tree output (
DefElem.arg_location,
NotifyStmt.payload_location,CreateSubscriptionStmt.conninfo_locationand
AlterSubscriptionStmt.conninfo_location). Like other location fields, these are
ignored for fingerprinting. - Applications that normalize untrusted query text should upgrade
- Reported by Paul Gerste (Cure53)
- When normalizing certain utility statements (e.g.
- Deparser: Add strict checking for unexpected pointer values
- This ensures that a bad input parse tree doesn't cause the deparser to crash, and
instead returns an error - Use cases that do not work with user input can define
PG_QUERY_DEPARSE_NO_STRICT_CHECKS
to turn off the most detailed checks, for slightly better performance - Reported by Paul Gerste (Cure53)
- This ensures that a bad input parse tree doesn't cause the deparser to crash, and
- Add stack overflow crash protection, error out instead #348
- Overly deep queries now return the standard Postgres "stack depth limit exceeded"
error instead of crashing the process - The allowed stack depth defaults to 100 kB, auto-sized up to 2 MB, and is
recalculated on each call, since callers may use threads with varying stack sizes - Stack depth is also checked when recursing directly into specific node types (e.g.
longUNIONchains), and inexprLocationduring raw parsing
- Overly deep queries now return the standard Postgres "stack depth limit exceeded"
- Switch Protobuf implementation from protobuf-c to upb
- upb is developed as part of the main Protobuf project, and is substantially faster,
in part due to its built-in arena allocation - upb also allows limiting parse depth for complex Protobuf input, avoiding crashes
- upb is developed as part of the main Protobuf project, and is substantially faster,
- Update to Postgres 18.6 release
- Add
pg_query_scan_tokensto get scan results without involving Protobuf- This allows pure C callers to walk a simple list of
PgQueryScanTokenstructs
- This allows pure C callers to walk a simple list of
- Ignore comments when parsing queries, only treat them as significant for scanning #378
- This fixes parse errors when comments are placed between related tokens
(e.g.NOT /* comment */ IN), or between string literals that get concatenated
- This fixes parse errors when comments are placed between related tokens
- Parser: Avoid quadratic memory use for rules that involve dotted names #374
- Return errors for PL/pgSQL statements without bodies #363
- This avoids an assertion failure or crash when
CREATE FUNCTIONorDOomits
its function body
- This avoids an assertion failure or crash when
- Fingerprinting: Add fingerprint options to
pg_query_fingerprint_opts#361- This is a breaking change for callers of
pg_query_fingerprint_opts,
which now takes a fingerprint options bitmask as a third argument - By default, relation references are fingerprinted following Postgres 18+
query ID behavior: in SELECT/DML statements the alias name replaces the
relation name when present, and schema names are ignored PG_QUERY_FINGERPRINT_RANGEVAR_IGNORE_ALIASESalways fingerprints
relation names and ignores aliasesPG_QUERY_FINGERPRINT_RANGEVAR_INCLUDE_SCHEMAalso fingerprints schema
names in SELECT/DML statements- Combining both flags (
PG_QUERY_FINGERPRINT_RANGEVAR_PG17_COMPAT)
matches how Postgres 17 and earlier calculate query IDs, and how
libpg_query 17 and earlier calculated fingerprints PG_QUERY_FINGERPRINT_FULL_RELNAMEfingerprints the full relation name,
instead of the default behavior of ignoring 2+ consecutive digits (which
groups queries on date/number-suffixed tables together)
- This is a breaking change for callers of
- Fingerprinting:
- Ignore
NOTIFYpayloads, similar to channel names #353 - Ignore role names (e.g. in
CREATE ROLE,DROP ROLE,GRANTandALTER ... RENAME) #357 - Include
BEGIN/START TRANSACTIONoptions (e.g. read-only, isolation level) #358 - Apply the depth cutoff when recursing into specific node types
- This changes fingerprints for set operation chains deeper than 100 levels,
which are now cut off consistently like other deeply nested nodes
- This changes fingerprints for set operation chains deeper than 100 levels,
- Ignore
- Deparser:
- pg_query_normalize:
- pg_query_summary:
- Fix a relation going missing when a CTE shares its name #367
- Fix memory leak when the tree walk throws an error
- Use built-in
strlcpy/strlcaton older glibc versions #339 - Add new OSS-Fuzz fuzzer targets for Protobuf processing and PL/pgSQL parsing #341 #343
% shasum -a 256 libpg_query-18.1.0*
2d3486cf6a9d3955b53e66235db39d62b54216c820cd392ab66dc842c5b1316d libpg_query-18.1.0.tar.gz
05ca8a633007479c75b2beebfce301184fb523fa5f34ead62a4335aa3346d0a1 libpg_query-18.1.0.zip