Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wrXKA-000PAp-1y for pgsql-bugs@arkaria.postgresql.org; Wed, 05 Aug 2026 08:50:06 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wrXK9-009kZy-1y for pgsql-bugs@arkaria.postgresql.org; Wed, 05 Aug 2026 08:50:05 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wrEFb-006TeN-1J for pgsql-bugs@lists.postgresql.org; Tue, 04 Aug 2026 12:28:07 +0000 Received: from mahout.postgresql.org ([2001:4800:3e1:1::227]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wrEFZ-00000000AdT-0hN0 for pgsql-bugs@lists.postgresql.org; Tue, 04 Aug 2026 12:28:07 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=postgresql.org; s=20171124; h=Message-ID:Date:Reply-To:Cc:From:To:Subject: Content-Transfer-Encoding:MIME-Version:Content-Type:Sender:Content-ID: Content-Description:In-Reply-To:References; bh=jNbVwYR8zt9KbQf5lHSym0/G0yWHFLTPdesvDWKuU/c=; b=UsPQSr/HT4DE63diA8N0F3K8N5 hWIOFxaYzKptioPOAzq8SbnLZdwUBiZcooA7mcz1v1tD82OohnblLd2bkYjwuRjHhX1ZT/mTG6SXO fZCI82JH6dtMArAmH6Jri57G2+YiljcZf1xJHmXtzYTzllmMR/NkFes3xO9TqOxQjfCHZq+MeGa8v vbbwcq8QKU2k/K/CbZZ3QEG+GEc+szavB5Sw8y1EHSFvtp7ZvwT3TFuYfOejgeIjIAQ0WE4xfWhqC SdJGTo0ZRLpAVQaBW00DhlKFQPdGpP5Nl6U/J+70hNYv0UqciFsoNwTWDCp+8i1N/9x+a/C7MYOnh N8KLZIRw==; Received: from wrigleys.postgresql.org ([2a02:16a8:dc51::60]) by mahout.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wrEFY-000U68-2V for pgsql-bugs@lists.postgresql.org; Tue, 04 Aug 2026 12:28:05 +0000 Received: from localhost ([127.0.0.1] helo=wrigleys.postgresql.org) by wrigleys.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1wrEFX-00000001UQV-28ao for pgsql-bugs@lists.postgresql.org; Tue, 04 Aug 2026 12:28:03 +0000 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Subject: BUG #19609: Server crashes when executing a JIT-compiled SQL function on s390x To: pgsql-bugs@lists.postgresql.org From: PG Bug reporting form Cc: a.prototype7@gmail.com Reply-To: a.prototype7@gmail.com, pgsql-bugs@lists.postgresql.org Date: Tue, 04 Aug 2026 12:27:18 +0000 Message-ID: <19609-e5278efcee2b4419@postgresql.org> X-Auto-Response-Suppress: All Auto-Submitted: auto-generated List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk The following bug has been logged on the website: Bug reference: 19609 Logged by: Artem Zarubin Email address: a.prototype7@gmail.com PostgreSQL version: 19beta2 Operating system: Ubuntu 24.04.4 LTS (s390x) Description: =20 Hello, I found a reproducible server crash when an SQL-language function is executed with LLVM JIT enabled on s390x. Tested commit: bad: 0392fb900eb89f52988cccd33046443c39c70d1c, PostgreSQL 19devel The server was built with: ./configure \ --prefix=3D/home/test/pginstall-vanilla18 \ --enable-debug \ --enable-cassert \ --with-llvm \ LLVM_CONFIG=3D/usr/bin/llvm-config-18 \ CLANG=3D/usr/bin/clang-18 Environment: Architecture: s390x OS: Ubuntu 24.04.4 LTS Kernel: Linux 6.8.0-136-generic GCC: 13.3.0 LLVM: 18.1.3 The following parameters are used by the attached TAP test: restart_after_crash =3D on jit =3D on Minimal SQL script to reproduce: CREATE FUNCTION type_text(oid) RETURNS text LANGUAGE sql STABLE AS $$ SELECT typname::text FROM pg_catalog.pg_type WHERE oid =3D $1 $$; SET jit =3D on; SET jit_above_cost =3D 0; SET jit_inline_above_cost =3D -1; SET jit_optimize_above_cost =3D -1; SET jit_expressions =3D on; SET jit_tuple_deforming =3D off; SELECT count(*) FROM ( SELECT oid FROM pg_catalog.pg_type ORDER BY oid LIMIT 7 ) AS t WHERE type_text(t.oid) =3D 'int2vector'; Expected result: count ------- 1 (1 row) Actual result: server closed the connection unexpectedly This probably means the server terminated abnormally before or while processing the request. connection to server was lost The server log contains: LOG: client backend (PID ...) was terminated by signal 11: Segmentation fault DETAIL: Failed process was running: SELECT count(*) ... Complete backtrace available from the core dump produced by the minimal reproducer: Program terminated with signal SIGSEGV, Segmentation fault. #0 0x000002aa3d0f29bc in cstring_to_text (s=3D0x0) at varlena.c:186 #1 name_text (fcinfo=3D) at varlena.c:2709 #2 0x000003ff9ae36126 in ?? () Backtrace stopped: frame did not save the PC si_signo =3D 11 (SIGSEGV) si_code =3D 1 (SEGV_MAPERR) si_addr =3D 0x0 r1 =3D 0x0 r11 =3D 0x0 pc =3D 0x2aa3d0f29bc The frame above name_text() contains JIT-generated code without unwind information. name_text() receives a NULL C-string pointer and crashes in cstring_to_text(). With jit=3Doff, the same query completes successfully and returns 1. LLVM inlining and PostgreSQL's expensive-query JIT optimization tier are not required: the crash is also reproduced with jit_inline_above_cost and jit_optimize_above_cost set to -1. The attached patch adds the reproducer as src/test/modules/test_misc/t/014_jit_s390x.pl. From the PostgreSQL source tree, I ran it against the installed build with: PG_INSTALL=3D/home/test/pginstall-vanilla18 PATH=3D"$PG_INSTALL/bin:$PATH" \ PERL5LIB=3D"$PWD/src/test/perl" \ PG_REGRESS=3D"$PWD/src/test/regress/pg_regress" \ prove -v src/test/modules/test_misc/t/014_jit_s390x.pl The TAP test fails as follows because the backend crashes: not ok 1 - JIT-compiled SQL function expression does not crash the backend got: '2' expected: '0' not ok 2 - JIT-compiled SQL function expression returns expected row got: '' expected: '1' The crash reproduced on every run of the final minimal test on this machine, including runs against newly initialized test clusters. --- Best regards, Artem Zarubin Postgres Professional: https://postgrespro.com/