Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wuQnB-000i2C-1V for pgsql-bugs@arkaria.postgresql.org; Thu, 13 Aug 2026 08:28:01 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wuQn9-00BvBI-0B for pgsql-bugs@arkaria.postgresql.org; Thu, 13 Aug 2026 08:28:00 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wuQn8-00BvB7-0r for pgsql-bugs@lists.postgresql.org; Thu, 13 Aug 2026 08:27:59 +0000 Received: from fhigh-b6-smtp.messagingengine.com ([202.12.124.157]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wuQn0-00000000Uxi-2P9x for pgsql-bugs@lists.postgresql.org; Thu, 13 Aug 2026 08:27:53 +0000 Received: from phl-compute-05.internal (phl-compute-05.internal [10.202.2.45]) by mailfhigh.stl.internal (Postfix) with ESMTP id A97E87A00D4; Thu, 13 Aug 2026 04:27:47 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-05.internal (MEProxy); Thu, 13 Aug 2026 04:27:47 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paquier.xyz; h= cc:cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm3; t=1786609667; x=1786696067; bh=fXg6ZmavDy Uu0Z4RnWC3rW/V2ASO0pTKTMPGXVFZLew=; b=N3Yxcfuqu6DyWXJD0oxXrcPqrI XejCViSoVlreAbdryMhTO8m5zvChjHsSlUezyfHy6pPNbK1v7xEpIgP0r9kNKkoy C/l+A3lauFrqsvCodA/tzC5Pxsen+3dSqq4C+0+aW4vT3wLRfCPzZB/aFrnrG6Iv NbAjPKVwVDR7WXDslhuGxiS9JQmohGggsXQMZ+9bdF4cHm7fVxaqFN7kogMakgma zv5HBCKoADlTrrU8kz/04DMEzTQPUae6dULTQJGfkWNPpRVieVUA050A+Y+5GQv4 vDQQsDznLzyF37EzqcI0IJmwGxJdAwWO8W0enx+JdNXt9xFqKeuxSWRFPGOQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t= 1786609667; x=1786696067; bh=fXg6ZmavDyUu0Z4RnWC3rW/V2ASO0pTKTMP GXVFZLew=; b=JEjVcwf/zfgrXNAmmFVyI4b8QCcYRzbZItPAChucm04qNYpi2B9 nGTHeRYEcQt7K9H4WYqURd2bD2UyYd/Jb6w4HGCMx1ykFbx/8zBiiL5FZnaWMgFS IokiyOdwpB+uBOjVMNiRb+GIkiDqVsD0pyWjE3dnhoSbv4Llj0lGIvEBQ46YnuyP vtGU9GMRGhF67SBfBVwi2uTNcyoqzdL9tTKWqVvz7GPcaJzMQsCzIKeyuFuNEXO3 Zu4/S6PSr+FTTHjcfQbcMNhQCRkrTO2BQ3z0gGMJ0VL5fVMQcvdcZXSzzDRQk7Sp AMc4CVNO68Ucznwyli036wB55crRNQDao7Q== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTE+B+f1R8jKxtSomNzvNEbVZlS7osPUX4oYm+bnZclok823nogYxhsIJRJ8inAQ7u IUtixJHfOY8KnZ2m3YyZdxeYKcxImpjGhTCfzQ883T0PXkdF1NdElSe46mGlX5JQ7sEVl6 3Byy9l0O4CU3uBSDV34ikK3KTyC4V7m++cUvkFJARab4LN+W1Geww/D/CvTV6kG35ngrUv uJW8bAMN8U6n+xYDuzEfKKOQ7TDfOZKGtRm2Nv/gYk+1FlM2dvz+Z3IxDT7720miU0qUt9 PZ9il7Vl9Y6Mq2CM27BV+qqBFpXRaN9PQyLuDYqJCOHcEyqLW7poeusLAH+d1m9QuGt4KV H2Mt8iuUE+OunILE7f+4YxX7d56wl6kjFv8tr8Xgnh1XGxhUMm74bHggaef1aY1wyBpvA2 us8wLfOLW1/wPNQe+OadGXW6lX4BzBPkdJIbXksq/EobWdJyfZr+OE0T4SqAddlCiPf/fx gKrP8nCLGNDNUtqh/Q5yopoL7+JfbOWT2jgSUsX75lKRJs+3xIxyU5oCf98XJGuVUnjwBZ AiXV5EcRUjqYBdikHOLKYDBfgBXk+NrM7WV1zaH00vPEodrb3nJmEkG/vWBaQe2PlsNZuj jo3N5OcMk6yOtFLbZeQVv0HOHGwIZ5jmgHrznUT6TzLIAuT9PYSWO+Rv9PmQ X-ME-Proxy: Feedback-ID: i0fe9450f:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Thu, 13 Aug 2026 04:27:45 -0400 (EDT) Date: Thu, 13 Aug 2026 17:27:42 +0900 From: Michael Paquier To: Andrey Rachitskiy Cc: ilia.kashintsev@gmail.com, pgsql-bugs@lists.postgresql.org Subject: Re: BUG #19612: SEGV in ParseConfigFp() in guc-file.l Message-ID: References: <19612-24ccb4fc6da7786f@postgresql.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="pRDgzlcuEbCwzIfu" Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --pRDgzlcuEbCwzIfu Content-Type: multipart/mixed; boundary="JdSeNvZYYmrltGA3" Content-Disposition: inline --JdSeNvZYYmrltGA3 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Tue, Aug 11, 2026 at 11:30:03AM +0500, Andrey Rachitskiy wrote: > Commit 4b496a3583e already marked the YY_BUFFER_STATE local volatile > for that longjmp path. Commit d663f150b5e made the scanner reentrant > and added a yyscan_t local used in the same cleanup. That local is > written after sigsetjmp and read after siglongjmp, but was not > volatile, so its value is indeterminate after the jump. Asan failure reproduced, thanks. Your patch has missed the following piece with yylex_init(): guc-file.l:387:17: warning: passing 'volatile yyscan_t *' (aka 'void *volatile *') to parameter of type 'yyscan_t *' (aka 'void **') discards qualifiers [-Wincompatible-pointer-types-discards-qualifiers] 387 | if (yylex_init(&scanner) != 0) I am wondering whether we should just use a non-volatile copy of "scanner", just for the sake of yylex_init(). The attached seems to work fine here with asan. Thoughts? -- Michael --JdSeNvZYYmrltGA3 Content-Type: text/plain; charset=us-ascii Content-Disposition: attachment; filename=asan-guc-file-l.patch Content-Transfer-Encoding: quoted-printable diff --git a/src/backend/utils/misc/guc-file.l b/src/backend/utils/misc/guc= -file.l index 58669a67e050..13cdba6cd7b6 100644 --- a/src/backend/utils/misc/guc-file.l +++ b/src/backend/utils/misc/guc-file.l @@ -354,7 +354,8 @@ ParseConfigFp(FILE *fp, const char *config_file, int de= pth, int elevel, unsigned int save_ConfigFileLineno =3D ConfigFileLineno; sigjmp_buf *save_GUC_flex_fatal_jmp =3D GUC_flex_fatal_jmp; sigjmp_buf flex_fatal_jmp; - yyscan_t scanner; + volatile yyscan_t scanner =3D NULL; + yyscan_t scanner_init; /* non-volatile for yylex_init() */ struct yyguts_t *yyg; /* needed for yytext macro */ volatile YY_BUFFER_STATE lex_buffer =3D NULL; int errorcount; @@ -384,8 +385,9 @@ ParseConfigFp(FILE *fp, const char *config_file, int de= pth, int elevel, ConfigFileLineno =3D 1; errorcount =3D 0; =20 - if (yylex_init(&scanner) !=3D 0) + if (yylex_init(&scanner_init) !=3D 0) elog(elevel, "yylex_init() failed: %m"); + scanner =3D scanner_init; yyg =3D (struct yyguts_t *) scanner; =20 lex_buffer =3D yy_create_buffer(fp, YY_BUF_SIZE, scanner); @@ -559,8 +561,11 @@ parse_error: } =20 cleanup: - yy_delete_buffer(lex_buffer, scanner); - yylex_destroy(scanner); + if (scanner) + { + yy_delete_buffer(lex_buffer, scanner); + yylex_destroy(scanner); + } /* Each recursion level must save and restore these static variables. */ ConfigFileLineno =3D save_ConfigFileLineno; GUC_flex_fatal_jmp =3D save_GUC_flex_fatal_jmp; --JdSeNvZYYmrltGA3-- --pRDgzlcuEbCwzIfu Content-Type: application/pgp-signature; name=signature.asc -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEG72nH6vTowiyblFKnvQgOdbyQH0FAmp9f/0ACgkQnvQgOdby QH1exg/6A30lZ4dlYMq+7qHqpICfe1XAkw4Klv4Oa3EvvbCeE6kLUV2zla5mqs6Q Vj4a8CnWvK0QkQ1/ePgWxrNJ+CV4iQlHHBae7bECz6zt3SF+kVAHx32GHUSlgKHF zpioOsB7Y0npGmWLB0vNR/GufVCtZBvZIA+72xcLQMJKytdcY18uqNjzfUVUsXUq LWznpXNrtKO0dSrj9LpJpeiKoyPDhFr2gV0AnGoNWlfp0929qy5C8lJIG5+G0FNm K4AU3wPfffxHpRlfT9UAdqGT/9dtxxStxda6RQZe0gG4uVYI/Z12B17mP3TXs+eG l5nA+VJvBGrJxmmrePtbeXPo0z83Z6SoIt4cOliKa1TlsN1cKPahrFWSw2oZpXck FeJ3N9a17FpL8xqeKr33lahmXqScxJXH7JiaAt8mQNybxRh8WaoakNGkMwZkyfyi Fu78OHMah0zLKE3rxxeZsf/LUg92/AlgQtmZY2nYFsGT6JwncDgbdy2uOoqyC7He qkzGjodlv0eg1eFZla39bHhNNb8iJLVjQYH5uUagg9IOUB4uCQxhtt8khqu7ncP7 fuXoN3CqF3fvnY5AraJH8kAD2Ea0jZzz3b5RTQqBp0MeUO3U/qL7c7N4aJV0zp7Q xAl+NOYwPAYlhsinrxLYogv/hWU062GphKQnwtK10ATUGfe9BwU= =K0Dr -----END PGP SIGNATURE----- --pRDgzlcuEbCwzIfu--