Skip to content

tokio-postgres: reject DataRow with a field count that differs from the columns - #36

Closed
wasifaleem wants to merge 1 commit into
MaterializeInc:masterfrom
Supermetal-Inc:tokio-postgres-datarow-field-count
Closed

wasifaleem wants to merge 1 commit into
MaterializeInc:masterfrom
Supermetal-Inc:tokio-postgres-datarow-field-count

Conversation

@wasifaleem

Copy link
Copy Markdown

Applies upstream rust-postgres 7a00ffa, released in tokio-postgres 0.7.18. A server that sends a DataRow with fewer fields than its row description declares now produces an error when the row is built, instead of a panic when a missing column is read. This fixes RUSTSEC-2026-0178 (GHSA-3gjw-f78c-vvpw) for this fork.

The upstream tests construct Column with a type_modifier field this fork does not have, so the test helper omits it.

🤖 Generated with Claude Code

…olumns

Row/SimpleQueryRow validated the requested index against the RowDescription
column count but indexed the ranges vector built from the DataRow field count,
which the server controls independently. A DataRow with fewer fields than
advertised columns made get/try_get (and a plain 0..row.len() loop) panic with
an out-of-bounds index. Validate the two counts match when the row is built so
the mismatch surfaces as a recoverable error instead.
@Supermetal-Inc Supermetal-Inc closed this by deleting the head repository Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants