[PATCH] ecpg: fix missing NULL check in ecpg_store_input

Started by Gladyshev Ilya6 days ago2 messageshackers
Beta feature

Hackorum builds and tests every patch posted to the lists, not only commitfest submissions. This is Hackorum's own CI rather than the PostgreSQL project's, and it is still under testing - please report anything that looks wrong.

won't retrysuccessCI history

This thread has been committed, so CI has stopped here. Anything below is the last result it produced.

You can run a PostgreSQL built from this patch straight from Docker, with no checkout and no build:

docker run --rm -p 5432:5432 ghcr.io/hackorum-dev/postgres-patch:t253488
psql -h localhost -U postgres

Built from patchset v1 (message #1), August 20, 2026 at 11:19 AM.

Every patchset is also pushed to a branch of our PostgreSQL fork, so you can check out the same tree CI built. Without a PostgreSQL checkout:

git clone --branch t253488_1 https://github.com/hackorum-dev/postgres.git

In a checkout you already have, add the fork once:

git remote add hackorum https://github.com/hackorum-dev/postgres.git

then, for this patchset and every later one:

git fetch hackorum t253488_1 && git checkout t253488_1

Patchset v1 (message #1) is on t253488_1

Jump to latest
#1Gladyshev Ilya
ilya.gladyshev@linux.dev

Hi all,

This is my first contribution, so please correct me if anything
is wrong.

During OOM, PGTYPESnumeric_to_asc() can return NULL even on valid
inputs, which can lead to a NULL deref in ecpg_store_input():

```
str = PGTYPESnumeric_to_asc(nval, nval->dscale);
slen = strlen(str);
```

This patch adds the NULL check, matching the surrounding code. This is
unlikely to be hit in practice, so it's more of a hardening than
a real fix.

---
Ilya Gladyshev // foxido.dev

Attachments:

t253488_1
0001-ecpg-Fix-NULL-pointer-crash-in-numeric-parameter-bin.patchtext/x-diff; name=0001-ecpg-Fix-NULL-pointer-crash-in-numeric-parameter-bin.patchDownload+6-2
#2Michael Paquier
michael@paquier.xyz
In reply to: Gladyshev Ilya (#1)
Re: [PATCH] ecpg: fix missing NULL check in ecpg_store_input

On Tue, Aug 18, 2026 at 10:58:25AM +0000, Gladyshev Ilya wrote:

This patch adds the NULL check, matching the surrounding code. This is
unlikely to be hit in practice, so it's more of a hardening than
a real fix.

Indeed, nice catch. I doubt that it's worth bothering outside of
HEAD for this class of failures due to the fact that they are unlikely
going to be hit in practice. Will do so.
--
Michael