postgres.git / summary / log / commit / refs
commit 64542957b44cce7e29f1979bcfbf04477234ea3c
Author: Peter Geoghegan <pg@bowt.ie>
Date: Thu Jul 16 22:55:35 2026 +0000
Fix wrong variable offset sanity check.
Commit c7aeb775 rewrote the HOT-chain offset sanity checks in three
places, but in heap_get_root_tuples it accidentally tested offnum -- the
outer loop variable, which is already bounded by the loop condition --
instead of nextoffnum, the offset actually passed to PageGetItemId. The
pre-c7aeb775 check tested nextoffnum.
With the check ineffective, a stale t_ctid could make PageGetItemId read
past the end of the line pointer array (which is data corruption that we
expect to be able to catch here).
Author: Peter Geoghegan <pg@bowt.ie>
Reported-by: Konstantin Knizhnik <knizhnik@garret.ru>
Discussion: https://postgr.es/m/87c7d8a4-3a82-4334-bee6-e8c2ad3f3293@garret.ru
Backpatch-through: 15
src/backend/access/heap/pruneheap.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/src/backend/access/heap/pruneheap.c b/src/backend/access/heap/pruneheap.c
index f00c9b81c1a..704187a7268 100644
--- a/src/backend/access/heap/pruneheap.c
+++ b/src/backend/access/heap/pruneheap.c
@@ -2374,14 +2374,14 @@ heap_get_root_tuples(Page page, OffsetNumber *root_offsets)
for (;;)
{
/* Sanity check (pure paranoia) */
- if (offnum < FirstOffsetNumber)
+ if (nextoffnum < FirstOffsetNumber)
break;
/*
* An offset past the end of page's line pointer array is possible
* when the array was truncated
*/
- if (offnum > maxoff)
+ if (nextoffnum > maxoff)
break;
lp = PageGetItemId(page, nextoffnum);
[parent: 048067c04c6c]