pg.ddx.io  pgsql-bugs@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Michael Paquier <michael@paquier.xyz>
To: Niall Newman <nn@turacolabs.com>
Cc: pgsql-bugs@lists.postgresql.org
Subject: Re: PostgreSQL 18.4 backend SIGSEGV in pgstat_gc_entry_refs() after caught DSM attach error
Date: Mon, 10 Aug 2026 08:42:06 +0900
Message-ID: <ankQTuCD9Gcq8wXn@paquier.xyz> (raw)
In-Reply-To: <anV8ftNMW3xyKSMG@paquier.xyz>
References: <2FDAA194-9CF3-4FD7-A450-F1A4BEB125F6@turacolabs.com>
	<anV8ftNMW3xyKSMG@paquier.xyz>

On Fri, Aug 07, 2026 at 03:34:38PM +0900, Michael Paquier wrote:
> 5) While on it, I think that we could do something about the
> dshash_find_or_insert() in pgstat_get_entry_ref(), where we could
> clean up the local reference if dshash_find_or_insert() returns NULL.
> That's content only worth on HEAD, as the problem is unlikely going to
> happen in practice, and that's only a local reference.
> 
> To summarize, I have fixed 2) with 4069df21beb8 backpatched down to
> v15, and did bf80a4c2d238 for 1) on HEAD.  3) is not necessary.  4)
> should have its own discussion, as it's a broader change impacting
> anything that uses DSA/DSM.  And I am planning to apply the attached
> for 5) only on HEAD as a follow-up improvement.

A consequence of 5) that I have missed during my initial lookup is
that it could be possible to finish with a NULL pointer dereference if
a concurrent backend has the idea to bump the refcount of the entry
that has a stale NULL shared_entry (due to entry reinit, for one, or
even a drop/create).  A OOM-ed backend calling pgstat_gc_entry_refs()
would be in trouble.

It's the first time I've heard about dshash_find_or_insert_extended().
That's kind of nice, perhaps it would make sense to extend its use in
other areas of the code..
--
Michael

Attachments:

  [application/pgp-signature] signature.asc (832B, ../ankQTuCD9Gcq8wXn@paquier.xyz/2-signature.asc)
  download

view thread (2+ messages)

Message-ID: <ankQTuCD9Gcq8wXn@paquier.xyz>
Permalink:  ../ankQTuCD9Gcq8wXn@paquier.xyz/
Also on:    postgresql.org/message-id/ankQTuCD9Gcq8wXn@paquier.xyz

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: michael@paquier.xyz, nn@turacolabs.com, pgsql-bugs@lists.postgresql.org
  Subject: Re: PostgreSQL 18.4 backend SIGSEGV in pgstat_gc_entry_refs() after caught DSM attach error
  In-Reply-To: <ankQTuCD9Gcq8wXn@paquier.xyz>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox