pgsql: Use snprintf not sprintf in pg_waldump's timestamptz_to_str.

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Use snprintf not sprintf in pg_waldump's timestamptz_to_str.
Date: 2018-06-16 18:59:01
Message-ID: [email protected]
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Use snprintf not sprintf in pg_waldump's timestamptz_to_str.

This could only cause an issue if strftime returned a ridiculously
long timezone name, which seems unlikely; and it wouldn't qualify
as a security problem even then, since pg_waldump (nee pg_xlogdump)
is a debug tool not part of the server. But gcc 8 has started issuing
warnings about it, so let's use snprintf and be safe.

Backpatch to 9.3 where this code was added.

Discussion: https://postgr.es/m/[email protected]

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/5d923eb29bb643e311680bab329363d8a9a9768a

Modified Files
--------------
src/bin/pg_waldump/compat.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Tom Lane 2018-06-16 19:34:30 pgsql: Use -Wno-format-truncation and -Wno-stringop-truncation, if avai
Previous Message Tom Lane 2018-06-16 18:11:19 pgsql: Fix some minor error-checking oversights in ParseFuncOrColumn().