agora inbox for pgsql-bugs@postgresql.org  
help / color / mirror / Atom feed
From: Konstantin Knizhnik <knizhnik@garret.ru>
To: PostgreSQL mailing lists <pgsql-bugs@lists.postgresql.org>
Subject: SIGSEGV in dynahash
Date: Sat, 15 Aug 2026 16:06:53 +0300
Message-ID: <d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru> (raw)

On PG19,|ShmemInitHash|always builds afixed-sizeshared hash with abump 
allocator(|ShmemHashAlloc|) whose|alloc_arg|is astack-localregion used 
only during|hash_create|. After init, that pointer is dead.

In|hash_search|, for every|HASH_ENTER|/|HASH_ENTER_NULL|, dynahash does 
thisbeforelookup:

dynahash.cLines927-937
if(action ==HASH_ENTER ||action ==HASH_ENTER_NULL)
{
if(hctl->freeList[0].nentries>(int64)hctl->max_bucket&&
!IS_PARTITIONED(hctl)&&!hashp->frozen&&
!has_seq_scans(hashp))
(void)expand_table(hashp);
}


It may cause SIGSEGV in case of using HASH_ENTER_NULL:


hash_search(HASH_ENTER_NULL)
→ expand_table → seg_alloc → SIGSEGV in libc (MemSet/alloc)


Pre-PG19, shared hashes used|ShmemAllocNoError|from the global pool, so 
a failed grow tended to return|NULL|/ error instead of faulting on a 
dead bump allocator.

It was introduced by commit 9fe9ecd516b — Allocate all parts of shmem 
hash table from a single contiguous area

Patch preventing extension of fixed dynahash is attached.
diff --git a/src/backend/utils/hash/dynahash.c b/src/backend/utils/hash/dynahash.c
index dc7ae64a5a9..727adfccf2d 100644
--- a/src/backend/utils/hash/dynahash.c
+++ b/src/backend/utils/hash/dynahash.c
@@ -927,11 +927,13 @@ hash_search_with_hash_value(HTAB *hashp,
 	if (action == HASH_ENTER || action == HASH_ENTER_NULL)
 	{
 		/*
-		 * Can't split if running in partitioned mode, nor if frozen, nor if
+		 * Can't split if running in partitioned mode, nor if frozen,
+		 * nor if fixed (in shared memory), nor if
 		 * table is the subject of any active hash_seq_search scans.
 		 */
 		if (hctl->freeList[0].nentries > (int64) hctl->max_bucket &&
 			!IS_PARTITIONED(hctl) && !hashp->frozen &&
+			!hctl->isfixed &&
 			!has_seq_scans(hashp))
 			(void) expand_table(hashp);
 	}


Attachments:

  [text/plain] 0001-prevent-fixed-dynahash-extension-20260815.patch (781B, ../d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru/3-0001-prevent-fixed-dynahash-extension-20260815.patch)
  download | inline diff:
diff --git a/src/backend/utils/hash/dynahash.c b/src/backend/utils/hash/dynahash.c
index dc7ae64a5a9..727adfccf2d 100644
--- a/src/backend/utils/hash/dynahash.c
+++ b/src/backend/utils/hash/dynahash.c
@@ -927,11 +927,13 @@ hash_search_with_hash_value(HTAB *hashp,
 	if (action == HASH_ENTER || action == HASH_ENTER_NULL)
 	{
 		/*
-		 * Can't split if running in partitioned mode, nor if frozen, nor if
+		 * Can't split if running in partitioned mode, nor if frozen,
+		 * nor if fixed (in shared memory), nor if
 		 * table is the subject of any active hash_seq_search scans.
 		 */
 		if (hctl->freeList[0].nentries > (int64) hctl->max_bucket &&
 			!IS_PARTITIONED(hctl) && !hashp->frozen &&
+			!hctl->isfixed &&
 			!has_seq_scans(hashp))
 			(void) expand_table(hashp);
 	}


view thread (6+ messages)  latest in thread

Message-ID: <d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru>
Permalink:  ../d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru/
Also on:    postgresql.org/message-id/d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: knizhnik@garret.ru, pgsql-bugs@lists.postgresql.org
  Subject: Re: SIGSEGV in dynahash
  In-Reply-To: <d59221f2-b3d2-41ad-8bf0-d581b42e4cba@garret.ru>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox