postgres.git / summary / log / commit / refs

commit    d8516db39dfa73042e3ba28f9efc78da4dd6792d
Author:   Melanie Plageman <melanieplageman@gmail.com>
Date:     Tue Sep 22 21:27:26 2026 +0000

    Assert correct VM page passed to pruning
    
    Before pruning a heap page, we get the current status of the
    corresponding VM page. If the passed in vmbuffer isn't the right one,
    visibilitymap_get_status() will silently unpin it and pin the correct
    page. Pruning assumes the caller manages the vmbuffer lifecycle, so this
    would leave the caller with a stale VM reference and would leak the new
    VM pin. To avoid mistakes in development, assert that the correct VM
    page is pinned before beginning.
    
    Reported-by: Melanie Plageman <melanieplageman@gmail.com>
    Reviewed-by: Andrey Borodin <x4mmm@yandex-team.ru>
    Discussion: https://postgr.es/m/CAAKRu_amj7qLF4c=9ijd=708Fu2G8gg-2EqwBu=aCdAHU2sPHg@mail.gmail.com
    Backpatch-through: 19


src/backend/access/heap/pruneheap.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/src/backend/access/heap/pruneheap.c b/src/backend/access/heap/pruneheap.c index 50f810c8830..c4db2e1335c 100644 --- a/src/backend/access/heap/pruneheap.c +++ b/src/backend/access/heap/pruneheap.c @@ -443,7 +443,13 @@ prune_freeze_setup(PruneFreezeParams *params, prstate->buffer = params->buffer; prstate->page = BufferGetPage(params->buffer); - Assert(BufferIsValid(params->vmbuffer)); + /* + * The caller must have pinned the VM page covering this heap block. If it + * doesn't have the correct page pinned, visibilitymap_get_status() will + * silently release the caller's pin and take its own, leaving the caller + * holding a stale buffer and leaking ours. + */ + Assert(visibilitymap_pin_ok(prstate->block, params->vmbuffer)); prstate->vmbuffer = params->vmbuffer; prstate->new_vmbits = 0; prstate->old_vmbits = visibilitymap_get_status(prstate->relation,