From: Peter Geoghegan <pg@bowt.ie>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Fix GIN VACUUM posting tree root split bug.
Date: Wed, 19 Aug 2026 16:31:23 +0000
Message-ID: <E1wwjCE-00000001Eyq-3fwc@gemulon.postgresql.org> (raw)
Fix GIN VACUUM posting tree root split bug.
ginVacuumPostingTreeLeaves swaps a shared buffer lock for an exclusive
one when it encounters a leaf page. It neglected to re-verify whether a
page that was initially a leaf root page became an internal page due to
a concurrent root page split (during the window when no lock was held).
It was therefore possible for GIN VACUUM to spuriously treat an internal
page as a leaf page, leading to data corruption. VACUUM could miss dead
TIDs that it was required to remove, leaving behind dangling references
in the index.
To fix, re-verify that a leaf page is still a leaf page after an
exclusive lock is acquired. If it isn't, drop our exclusive lock and
acquire a shared lock so that the non-leaf root page gets processed in
the usual way.
Oversight in commit fd83c83d, which fixed a deadlock bug in GIN posting
tree vacuuming.
Author: Peter Geoghegan <pg@bowt.ie>
Reviewed-by: Andrey Borodin <x4mmm@yandex-team.ru>
Discussion: https://postgr.es/m/CAH2-Wz=RBpJTQgvOxr6C=J04dExmFSt1E3F-r+cRTQ56hEotkg@mail.gmail.com
Backpatch-through: 14
Branch
------
REL_18_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/9900966c7d598fedb72850c4d0db2d5ac6986d37
Modified Files
--------------
src/backend/access/gin/ginvacuum.c | 10 ++++++++++
1 file changed, 10 insertions(+)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-committers@postgresql.org
Cc: pg@bowt.ie, pgsql-committers@lists.postgresql.org
Subject: Re: pgsql: Fix GIN VACUUM posting tree root split bug.
In-Reply-To: <E1wwjCE-00000001Eyq-3fwc@gemulon.postgresql.org>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox