From: Grigorev Jurij <ju.grigorev@ftdata.ru>
To: Michael Paquier <michael@paquier.xyz>
Cc: Rahul Yadav <rahul@rhyadav.com>
Cc: pgsql-hackers@lists.postgresql.org <pgsql-hackers@lists.postgresql.org>
Subject: Re: BUG #19599: RestoreBlockImage: the decode cross-checks never bound hole_offset + hole_length against BLCKSZ
Date: Thu, 1 Oct 2026 03:18:11 +0000
Message-ID: <f416177295864b52a2351cb44b9418a0@localhost.localdomain> (raw)
In-Reply-To: <ar2hA_b1Be7VsZdP@paquier.xyz>
References: <cc0a5886d2a74f99ae58c1647ea5ed8b@localhost.localdomain>
<CAJJjRReEjgkbm_J9avW=z+eqz6tjyjJRfBmyQvfSx04td-OEvQ@mail.gmail.com>
<cd00a0536c674fac9e5dd9f4e27ae868@localhost.localdomain>
<ar2hA_b1Be7VsZdP@paquier.xyz>
Hi Michael,
Thanks for looking! I agree XLogRecordAssemble() never writes
such a hole, CRC catches accidental corruption, and core WAL is
trusted.
My only point was that DecodeXLogRecord() already distrusts these
fields enough to cross-check them: it rejects hole_offset == 0,
hole_length == 0, bimg_len == BLCKSZ when HAS_HOLE is set, and
non-zero hole fields when it is not set. Bounding
hole_offset + hole_length against BLCKSZ just completes that
existing family of checks. Rahul's repro shows a re-CRCed record
still passes decode and then crashes pg_waldump --save-fullpage.
I agree the test in 0002 is quite large for such a small check --
happy to drop it entirely. To keep this minimal, we could keep
just the two-line check in DecodeXLogRecord() with no extra test --
the existing HAS_HOLE error message, no new paths.
I don't insist on the test or backpatch -- if you prefer, let's
keep only the decode check, or close it if you think even that
is not wanted. Should xlogreader be robust here, or may
RestoreBlockImage() assume trusted input after CRC?
I understand from your message that you lean towards this not
being needed, given trusted WAL, CRC and the insertion bounds --
just wanted to understand where the line is. Happy to update
or close as you suggest.
Kind regards,
Yuriy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-bugs@postgresql.org
Cc: ju.grigorev@ftdata.ru, michael@paquier.xyz, rahul@rhyadav.com, pgsql-hackers@lists.postgresql.org
Subject: Re: BUG #19599: RestoreBlockImage: the decode cross-checks never bound hole_offset + hole_length against BLCKSZ
In-Reply-To: <f416177295864b52a2351cb44b9418a0@localhost.localdomain>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox