Reject CR and LF characters in backup labels

The label is written as one line of the backup_label file.  A label
with a newline added extra lines to the file, and recovery could read
those as other fields, failing on them.  Characters could also be
injected to make recovery behave in inconsistent ways.

Trying to use such characters in label names is now rejected, for both
pg_backup_start() and BASE_BACKUP.

As this is arguably a behavior change, no backpatch is done.  I also
seriously doubt that anybody is relying on the behavior of pushing some
arbitrary data to backup_label files, and even if they do, it would be a
very bad idea to contradict what the backend decides to generate.

Reported-by: Shallow <[email protected]>
Author: Shihao Zhong <[email protected]>
Discussion: https://postgr.es/m/[email protected]

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/e624e1fd13dcc754deebfd8a5be8f6fa578e17da

Modified Files
--------------
src/backend/access/transam/xlog.c         |  5 +++++
src/test/recovery/t/020_archive_status.pl | 13 +++++++++++++
2 files changed, 18 insertions(+)

Reply via email to