Skip to content

SYSTEM Cited by 1 source

PostGIS

What it is

PostGIS is the geospatial extension to PostgreSQL, providing spatial data types (geometry, geography, raster), spatial indexes (GiST, SP-GiST), and hundreds of spatial functions (projection, topology, tile production, grid generation). It is the de facto open-source standard for managing geospatial data. Homepage: postgis.net.

PostGIS is a canonical third-party instance of the Postgres extension over fork pattern: originally released 2001, continuously developed, and runs on mainline Postgres via the public extension API — no fork.

Tile-production API surface (relevant to vector-tile serving)

The functions systems/pg-tileserv and similar thin HTTP shims lean on to turn PostGIS tables and SQL functions into Mapbox Vector Tiles:

  • ST_TileEnvelope(z, x, y) — return the Web-Mercator envelope geometry for a given tile coordinate.
  • ST_AsMVTGeom(geom, envelope) — clip/transform a geometry into the MVT tile coordinate space.
  • ST_AsMVT(row_set, layer_name) — encode a row set (with MVT-geom column + attribute columns) as a binary MVT Protocol Buffer blob.
  • ST_HexagonGrid(size, bounds) — generate a hexagon grid of a given size covering a bounds geometry. Returned as a set of (geom, i, j) rows.
  • ST_Transform(geom, srid) — reproject a geometry between spatial reference systems (e.g. Web-Mercator 3857 ↔ WGS84 4326).
  • ST_Centroid(geom) — reduce a polygon to its centroid point (commonly used to turn polygon data into point-in-hex joinable form to avoid double-counting).

address_standardizer — the tenant-reachable memory-safety surface

address_standardizer is a small PostGIS sub-extension that normalizes an unstructured address (e.g. 123 Main St) into a canonical form. On managed Postgres it is on the set of extensions a normal tenant can install and call — which makes any memory-safety bug in it directly reachable from an ordinary customer role, no special privilege required.

In 2026 an external researcher found a classic memory-safety flaw in it: a caller-controlled value (part of a grammar "rule" the caller supplies) indexes a fixed-size internal array without a bounds check, yielding an out-of-bounds memory access. Because PostGIS is the de-facto standard shipped by "almost every" managed provider, "a memory-corruption vulnerability in a widely deployed extension is effectively a memory-corruption vulnerability in PostgreSQL itself" — one bug, industry-wide attack surface. This is the flip side of the extension-over-fork norm: shared extension code means a shared exposure. The reachable bug was hardened downstream by affected platforms (via a downstream patch lever) and the root cause driven upstream. (Source: sources/2026-09-01-databricks-collaboration-makes-us-all-stronger.)

Seen in

  • sources/2026-09-01-databricks-collaboration-makes-us-all-stronger — memory-safety bug in the address_standardizer sub-extension, reachable by a normal tenant role on managed Postgres (Lakebase, Neon); Databricks owned the exposure, patched downstream, and upstreamed the fix.
  • Zalando Postgres Operator team (Nikolai Averkiev, 2021-12-01) canonicalises the claim "these days PostGIS can take over most of the middleware's job and produce map tiles for you". Worked example: a population_hexagons(z,x,y,step) PL/SQL function over ST_TileEnvelope + ST_HexagonGrid
  • LATERAL join to a Eurostat 1 km² population grid + ST_AsMVT returns a PBF blob directly from the database. Deployment context: PostGIS pre-compiled into the Spilo Docker image the Postgres Operator runs; installed declaratively into a named schema via preparedDatabases.<db>.extensions.postgis: <schema> on the Postgresql custom resource. First wiki canonical page.
  • systems/postgresql — the host database.
  • systems/pg-tileserv — the most commonly-paired HTTP shim that serves PostGIS tile outputs to web maps.
  • systems/leaflet · systems/openstreetmap — the typical frontend substrate. Spilo — the Kubernetes + container delivery path Zalando documents.
  • vector-tiles — the format PostGIS produces.
  • postgres-extension-over-fork — PostGIS is the canonical third-party instance.
  • database-as-tile-server-middleware-replacement — the architectural pattern PostGIS enables.
  • systems/lakebase · systems/neon — managed-Postgres surfaces that ship PostGIS to tenants.
  • concepts/memory-safety — the address_standardizer bug class.
  • own-your-exposure-not-just-your-code — why the platform shipping PostGIS owns its bugs.
  • downstream-patch-lever-for-shipped-oss · patterns/upstream-the-fix — how the reachable bug was contained then fixed.
Last updated · 766 distilled / 2,225 read