]> git.ipfire.org Git - thirdparty/postgresql.git/commit
Add missing connection validation in ECPG
authorAndrew Dunstan <andrew@dunslane.net>
Fri, 1 May 2026 19:12:28 +0000 (15:12 -0400)
committerAndrew Dunstan <andrew@dunslane.net>
Fri, 1 May 2026 19:12:28 +0000 (15:12 -0400)
commitc34a280c85b39b6e875afa56542a055d2b90b640
tree47f1d6369892723a73209547628edcb3213dc223
parentb772f3fcad1870731020dbe56713c616abc5dc26
Add missing connection validation in ECPG

ECPGdeallocate_all(), ECPGprepared_statement(), ECPGget_desc(), and
ecpg_freeStmtCacheEntry() could crash with a SIGSEGV when called
without an established connection (for example, when EXEC SQL CONNECT
was forgotten or a non-existent connection name was used), because
they dereferenced the result of ecpg_get_connection() without first
checking it for NULL.

Each site is fixed in the style of the surrounding code.

New tests are added for these conditions.

Author: Shruthi Gowda <gowdashru@gmail.com>
Reviewed-by: Tom Lane <tgl@sss.pgh.pa.us>
Reviewed-by: Fujii Masao <masao.fujii@gmail.com>
Reviewed-by: Mahendra Singh Thalor <mahi6run@gmail.com>
Reviewed-by: Nishant Sharma <nishant.sharma@enterprisedb.com>
Discussion: https://postgr.es/m/3007317.1765210195@sss.pgh.pa.us
Backpatch-through: 14
src/interfaces/ecpg/ecpglib/descriptor.c
src/interfaces/ecpg/ecpglib/prepare.c
src/interfaces/ecpg/test/connect/.gitignore
src/interfaces/ecpg/test/connect/Makefile
src/interfaces/ecpg/test/connect/meson.build
src/interfaces/ecpg/test/connect/test6.pgc [new file with mode: 0644]
src/interfaces/ecpg/test/ecpg_schedule
src/interfaces/ecpg/test/expected/connect-test6.c [new file with mode: 0644]
src/interfaces/ecpg/test/expected/connect-test6.stderr [new file with mode: 0644]
src/interfaces/ecpg/test/expected/connect-test6.stdout [new file with mode: 0644]