• Heikki Linnakangas's avatar
    stringToNode() and deparse_expression_pretty() crash on invalid input, · 350ab443
    Heikki Linnakangas authored
    but we have nevertheless exposed them to users via pg_get_expr(). It would
    be too much maintenance effort to rigorously check the input, so put a hack
    in place instead to restrict pg_get_expr() so that the argument must come
    from one of the system catalog columns known to contain valid expressions.
    
    Per report from Rushabh Lathia. Backpatch to 7.4 which is the oldest
    supported version at the moment.
    350ab443
fastpath.c 16.7 KB