agora inbox for pgsql-bugs@postgresql.org
help / color / mirror / Atom feedFrom: Konstantin Knizhnik <knizhnik@garret.ru>
To: PostgreSQL mailing lists <pgsql-bugs@lists.postgresql.org>
Subject: SIGSEGV in dynahash
Date: Sat, 15 Aug 2026 16:06:53 +0300
Message-ID: <d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru> (raw)
On PG19,|ShmemInitHash|always builds afixed-sizeshared hash with abump
allocator(|ShmemHashAlloc|) whose|alloc_arg|is astack-localregion used
only during|hash_create|. After init, that pointer is dead.
In|hash_search|, for every|HASH_ENTER|/|HASH_ENTER_NULL|, dynahash does
thisbeforelookup:
dynahash.cLines927-937
if(action ==HASH_ENTER ||action ==HASH_ENTER_NULL)
{
if(hctl->freeList[0].nentries>(int64)hctl->max_bucket&&
!IS_PARTITIONED(hctl)&&!hashp->frozen&&
!has_seq_scans(hashp))
(void)expand_table(hashp);
}
It may cause SIGSEGV in case of using HASH_ENTER_NULL:
hash_search(HASH_ENTER_NULL)
→ expand_table → seg_alloc → SIGSEGV in libc (MemSet/alloc)
Pre-PG19, shared hashes used|ShmemAllocNoError|from the global pool, so
a failed grow tended to return|NULL|/ error instead of faulting on a
dead bump allocator.
It was introduced by commit 9fe9ecd516b — Allocate all parts of shmem
hash table from a single contiguous area
Patch preventing extension of fixed dynahash is attached.
diff --git a/src/backend/utils/hash/dynahash.c b/src/backend/utils/hash/dynahash.c
index dc7ae64a5a9..727adfccf2d 100644
--- a/src/backend/utils/hash/dynahash.c
+++ b/src/backend/utils/hash/dynahash.c
@@ -927,11 +927,13 @@ hash_search_with_hash_value(HTAB *hashp,
if (action == HASH_ENTER || action == HASH_ENTER_NULL)
{
/*
- * Can't split if running in partitioned mode, nor if frozen, nor if
+ * Can't split if running in partitioned mode, nor if frozen,
+ * nor if fixed (in shared memory), nor if
* table is the subject of any active hash_seq_search scans.
*/
if (hctl->freeList[0].nentries > (int64) hctl->max_bucket &&
!IS_PARTITIONED(hctl) && !hashp->frozen &&
+ !hctl->isfixed &&
!has_seq_scans(hashp))
(void) expand_table(hashp);
}
Attachments:
[text/plain] 0001-prevent-fixed-dynahash-extension-20260815.patch (781B, ../d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru/3-0001-prevent-fixed-dynahash-extension-20260815.patch)
download | inline diff:
diff --git a/src/backend/utils/hash/dynahash.c b/src/backend/utils/hash/dynahash.c
index dc7ae64a5a9..727adfccf2d 100644
--- a/src/backend/utils/hash/dynahash.c
+++ b/src/backend/utils/hash/dynahash.c
@@ -927,11 +927,13 @@ hash_search_with_hash_value(HTAB *hashp,
if (action == HASH_ENTER || action == HASH_ENTER_NULL)
{
/*
- * Can't split if running in partitioned mode, nor if frozen, nor if
+ * Can't split if running in partitioned mode, nor if frozen,
+ * nor if fixed (in shared memory), nor if
* table is the subject of any active hash_seq_search scans.
*/
if (hctl->freeList[0].nentries > (int64) hctl->max_bucket &&
!IS_PARTITIONED(hctl) && !hashp->frozen &&
+ !hctl->isfixed &&
!has_seq_scans(hashp))
(void) expand_table(hashp);
}
view thread (6+ messages) latest in thread
Message-ID: <d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru>
Permalink: ../d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru/
Also on: postgresql.org/message-id/d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-bugs@postgresql.org
Cc: knizhnik@garret.ru, pgsql-bugs@lists.postgresql.org
Subject: Re: SIGSEGV in dynahash
In-Reply-To: <d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox