agora inbox for pgsql-bugs@postgresql.org
help / color / mirror / Atom feedFrom: Michael Paquier <michael@paquier.xyz>
To: Grigorev Jurij <ju.grigorev@ftdata.ru>
Cc: Rahul Yadav <rahul@rhyadav.com>
Cc: pgsql-hackers@lists.postgresql.org <pgsql-hackers@lists.postgresql.org>
Subject: Re: BUG #19599: RestoreBlockImage: the decode cross-checks never bound hole_offset + hole_length against BLCKSZ
Date: Thu, 1 Oct 2026 08:53:40 +0900
Message-ID: <ar2hA_b1Be7VsZdP@paquier.xyz> (raw)
In-Reply-To: <cd00a0536c674fac9e5dd9f4e27ae868@localhost.localdomain>
References: <cc0a5886d2a74f99ae58c1647ea5ed8b@localhost.localdomain>
<CAJJjRReEjgkbm_J9avW=z+eqz6tjyjJRfBmyQvfSx04td-OEvQ@mail.gmail.com>
<cd00a0536c674fac9e5dd9f4e27ae868@localhost.localdomain>
On Tue, Sep 29, 2026 at 08:37:02AM +0000, Grigorev Jurij wrote:
> Thank you very much for the thorough review and testing -- the
> crash-recovery matrix (pglz/lz4/zstd/off + consistency checking) and
> especially the crafted-record repro with pg_waldump --save-fullpage
> crashing without the patch are super convincing. And thanks for
> confirming the back-patch safety argument.
>
> v2 attached, addressing all your points:
XLogRecordAssemble() in xloginsert.c enforces a size policy already
when a page image needs to be included in a record (REGBUF_STANDARD
case, for both the "lower" and "upper" cases). The argument of a
corrupted record does not stand, a CRC32 check would complain before
we ever reach this path. The hand-made record record argument is also
something I have a hard time to buy, because WAL data is trusted.
So, I don't understand what this patch buys us at all, except more
complexity in the replay path.
There may be an argument for the xlogreader facility, but this relies
on the premise that incorrect WAL records are a thing out there.
Again here comes the CRC check in the record header and the WAL
insertion enforcing already some bounds. This feels like test bloat
to me.
--
Michael
Attachments:
[application/pgp-signature] signature.asc (832B, ../ar2hA_b1Be7VsZdP@paquier.xyz/2-signature.asc)
download
view thread (7+ messages) latest in thread
Message-ID: <ar2hA_b1Be7VsZdP@paquier.xyz>
Permalink: ../ar2hA_b1Be7VsZdP@paquier.xyz/
Also on: postgresql.org/message-id/ar2hA_b1Be7VsZdP@paquier.xyz
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-bugs@postgresql.org
Cc: michael@paquier.xyz, ju.grigorev@ftdata.ru, rahul@rhyadav.com, pgsql-hackers@lists.postgresql.org
Subject: Re: BUG #19599: RestoreBlockImage: the decode cross-checks never bound hole_offset + hole_length against BLCKSZ
In-Reply-To: <ar2hA_b1Be7VsZdP@paquier.xyz>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox