postgres.git / summary / log / commit / refs

commit    64542957b44cce7e29f1979bcfbf04477234ea3c
Author:   Peter Geoghegan <pg@bowt.ie>
Date:     Thu Jul 16 22:55:35 2026 +0000

    Fix wrong variable offset sanity check.
    
    Commit c7aeb775 rewrote the HOT-chain offset sanity checks in three
    places, but in heap_get_root_tuples it accidentally tested offnum -- the
    outer loop variable, which is already bounded by the loop condition --
    instead of nextoffnum, the offset actually passed to PageGetItemId.  The
    pre-c7aeb775 check tested nextoffnum.
    
    With the check ineffective, a stale t_ctid could make PageGetItemId read
    past the end of the line pointer array (which is data corruption that we
    expect to be able to catch here).
    
    Author: Peter Geoghegan <pg@bowt.ie>
    Reported-by: Konstantin Knizhnik <knizhnik@garret.ru>
    Discussion: https://postgr.es/m/87c7d8a4-3a82-4334-bee6-e8c2ad3f3293@garret.ru
    Backpatch-through: 15


src/backend/access/heap/pruneheap.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/backend/access/heap/pruneheap.c b/src/backend/access/heap/pruneheap.c index f00c9b81c1a..704187a7268 100644 --- a/src/backend/access/heap/pruneheap.c +++ b/src/backend/access/heap/pruneheap.c @@ -2374,14 +2374,14 @@ heap_get_root_tuples(Page page, OffsetNumber *root_offsets) for (;;) { /* Sanity check (pure paranoia) */ - if (offnum < FirstOffsetNumber) + if (nextoffnum < FirstOffsetNumber) break; /* * An offset past the end of page's line pointer array is possible * when the array was truncated */ - if (offnum > maxoff) + if (nextoffnum > maxoff) break; lp = PageGetItemId(page, nextoffnum); [parent: 048067c04c6c]