SYSTEM Cited by 1 source
PostGIS¶
What it is¶
PostGIS is the geospatial extension to
PostgreSQL, providing spatial
data types (geometry, geography, raster), spatial
indexes (GiST, SP-GiST), and hundreds of spatial
functions (projection, topology, tile production, grid
generation). It is the de facto open-source standard
for managing geospatial data.
Homepage: postgis.net.
PostGIS is a canonical third-party instance of the Postgres extension over fork pattern: originally released 2001, continuously developed, and runs on mainline Postgres via the public extension API — no fork.
Tile-production API surface (relevant to vector-tile serving)¶
The functions systems/pg-tileserv and similar thin HTTP shims lean on to turn PostGIS tables and SQL functions into Mapbox Vector Tiles:
ST_TileEnvelope(z, x, y)— return the Web-Mercator envelope geometry for a given tile coordinate.ST_AsMVTGeom(geom, envelope)— clip/transform a geometry into the MVT tile coordinate space.ST_AsMVT(row_set, layer_name)— encode a row set (with MVT-geom column + attribute columns) as a binary MVT Protocol Buffer blob.ST_HexagonGrid(size, bounds)— generate a hexagon grid of a given size covering a bounds geometry. Returned as a set of(geom, i, j)rows.ST_Transform(geom, srid)— reproject a geometry between spatial reference systems (e.g. Web-Mercator 3857 ↔ WGS84 4326).ST_Centroid(geom)— reduce a polygon to its centroid point (commonly used to turn polygon data into point-in-hex joinable form to avoid double-counting).
address_standardizer — the tenant-reachable memory-safety surface¶
address_standardizer is a small PostGIS sub-extension that normalizes an
unstructured address (e.g. 123 Main St) into a canonical form. On managed
Postgres it is on the set of extensions a normal tenant can install and call
— which makes any memory-safety bug in it directly reachable from an ordinary
customer role, no special privilege required.
In 2026 an external researcher found a classic memory-safety flaw in it: a caller-controlled value (part of a grammar "rule" the caller supplies) indexes a fixed-size internal array without a bounds check, yielding an out-of-bounds memory access. Because PostGIS is the de-facto standard shipped by "almost every" managed provider, "a memory-corruption vulnerability in a widely deployed extension is effectively a memory-corruption vulnerability in PostgreSQL itself" — one bug, industry-wide attack surface. This is the flip side of the extension-over-fork norm: shared extension code means a shared exposure. The reachable bug was hardened downstream by affected platforms (via a downstream patch lever) and the root cause driven upstream. (Source: sources/2026-09-01-databricks-collaboration-makes-us-all-stronger.)
Seen in¶
- sources/2026-09-01-databricks-collaboration-makes-us-all-stronger —
memory-safety bug in the
address_standardizersub-extension, reachable by a normal tenant role on managed Postgres (Lakebase, Neon); Databricks owned the exposure, patched downstream, and upstreamed the fix. - Zalando Postgres Operator team (Nikolai Averkiev,
2021-12-01) canonicalises the claim "these days PostGIS
can take over most of the middleware's job and produce
map tiles for you". Worked example: a
population_hexagons(z,x,y,step)PL/SQL function overST_TileEnvelope+ST_HexagonGrid - LATERAL join to a Eurostat 1 km² population grid +
ST_AsMVTreturns a PBF blob directly from the database. Deployment context: PostGIS pre-compiled into the Spilo Docker image the Postgres Operator runs; installed declaratively into a named schema viapreparedDatabases.<db>.extensions.postgis: <schema>on thePostgresqlcustom resource. First wiki canonical page.
Related¶
- systems/postgresql — the host database.
- systems/pg-tileserv — the most commonly-paired HTTP shim that serves PostGIS tile outputs to web maps.
- systems/leaflet · systems/openstreetmap — the typical frontend substrate. Spilo — the Kubernetes + container delivery path Zalando documents.
- vector-tiles — the format PostGIS produces.
- postgres-extension-over-fork — PostGIS is the canonical third-party instance.
- database-as-tile-server-middleware-replacement — the architectural pattern PostGIS enables.
- systems/lakebase · systems/neon — managed-Postgres surfaces that ship PostGIS to tenants.
- concepts/memory-safety — the
address_standardizerbug class. - own-your-exposure-not-just-your-code — why the platform shipping PostGIS owns its bugs.
- downstream-patch-lever-for-shipped-oss · patterns/upstream-the-fix — how the reachable bug was contained then fixed.