Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commit5d923eb

Browse files
committed
Use snprintf not sprintf in pg_waldump's timestamptz_to_str.
This could only cause an issue if strftime returned a ridiculouslylong timezone name, which seems unlikely; and it wouldn't qualifyas a security problem even then, since pg_waldump (nee pg_xlogdump)is a debug tool not part of the server. But gcc 8 has started issuingwarnings about it, so let's use snprintf and be safe.Backpatch to 9.3 where this code was added.Discussion:https://postgr.es/m/21789.1529170195@sss.pgh.pa.us
1 parent0dcf68e commit5d923eb

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

‎src/bin/pg_waldump/compat.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,8 @@ timestamptz_to_str(TimestampTz dt)
5858
strftime(ts,sizeof(ts),"%Y-%m-%d %H:%M:%S",ltime);
5959
strftime(zone,sizeof(zone),"%Z",ltime);
6060

61-
sprintf(buf,"%s.%06d %s",ts, (int) (dt %USECS_PER_SEC),zone);
61+
snprintf(buf,sizeof(buf),"%s.%06d %s",
62+
ts, (int) (dt %USECS_PER_SEC),zone);
6263

6364
returnbuf;
6465
}

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp