pg.ddx.io pgsql-committers@postgresql.org mailing list archivehelp / color / mirror / Atom feed
pgsql: Fix crash in subscription refresh on concurrent relation drop. 5+ messages / 1 participants [nested] [flat]
* pgsql: Fix crash in subscription refresh on concurrent relation drop. @ 2026-08-26 19:05 Masahiko Sawada <msawada@postgresql.org> 0 siblings, 0 replies; 5+ messages in thread From: Masahiko Sawada @ 2026-08-26 19:05 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix crash in subscription refresh on concurrent relation drop. Commit 46b4f5c11b0 made the logical replication origin checks quote the schema and relation names they interpolate into the query sent to the publisher. Those names can be NULL, which that commit overlooked. AlterSubscription_refresh() collects the OIDs of the relations already present in pg_subscription_rel and hands them to check_publications_origin_tables() and check_publications_origin_sequences(), which append the schema-qualified name of each one to the query so that already-subscribed relations are excluded from the check. The relations are never locked, so one of them can be dropped concurrently before its name is read, and get_rel_name() and get_namespace_name() return NULL. quote_literal_cstr() dereferences it and crashes the backend. This commit fixes this by skipping a relation whose name is no longer available. A dropped relation is not synchronized anyway, and the appended clauses only exclude relations from a check whose sole effect is a WARNING, so omitting one can at most produce a spurious WARNING. The window is reachable from ALTER SUBSCRIPTION ... REFRESH PUBLICATION and from SET, ADD and DROP PUBLICATION, which refresh by default, but only when copy_data is true and origin is none. Backpatch to v16 as commit 46b4f5c11b0 was back-patched that far. The sequence path exists only in v19 and later. The test is applied to v19 and later only. Adding it to v17 and v18 would require enabling injection point support in src/test/subscription there, and v16 predates injection points entirely. That is more test infrastructure churn on stable branches than this fix warrants. Reported-by: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Author: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Co-authored-by: Bharath Rupireddy <bharath.rupireddyforpostgres@gmail.com> Reviewed-by: Ajin Cherian <itsajin@gmail.com> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Discussion: https://postgr.es/m/CAHg+QDcd_o3707Ey8c8b7HkE-t14g8c0tk8ME3ctywDsh3ut8g@mail.gmail.com Backpatch-through: 16 Branch ------ master Details ------- https://git.postgresql.org/pg/commitdiff/f3b0bb29834edb9242b180ea7289013a92c9f225 Modified Files -------------- src/backend/commands/subscriptioncmds.c | 44 ++++++++++++++--- src/test/subscription/t/100_bugs.pl | 86 +++++++++++++++++++++++++++++++++ 2 files changed, 122 insertions(+), 8 deletions(-) ^ permalink raw reply [nested|flat] 5+ messages in thread
* pgsql: Fix crash in subscription refresh on concurrent relation drop. @ 2026-08-26 19:05 Masahiko Sawada <msawada@postgresql.org> 0 siblings, 0 replies; 5+ messages in thread From: Masahiko Sawada @ 2026-08-26 19:05 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix crash in subscription refresh on concurrent relation drop. Commit 46b4f5c11b0 made the logical replication origin checks quote the schema and relation names they interpolate into the query sent to the publisher. Those names can be NULL, which that commit overlooked. AlterSubscription_refresh() collects the OIDs of the relations already present in pg_subscription_rel and hands them to check_publications_origin_tables() and check_publications_origin_sequences(), which append the schema-qualified name of each one to the query so that already-subscribed relations are excluded from the check. The relations are never locked, so one of them can be dropped concurrently before its name is read, and get_rel_name() and get_namespace_name() return NULL. quote_literal_cstr() dereferences it and crashes the backend. This commit fixes this by skipping a relation whose name is no longer available. A dropped relation is not synchronized anyway, and the appended clauses only exclude relations from a check whose sole effect is a WARNING, so omitting one can at most produce a spurious WARNING. The window is reachable from ALTER SUBSCRIPTION ... REFRESH PUBLICATION and from SET, ADD and DROP PUBLICATION, which refresh by default, but only when copy_data is true and origin is none. Backpatch to v16 as commit 46b4f5c11b0 was back-patched that far. The sequence path exists only in v19 and later. The test is applied to v19 and later only. Adding it to v17 and v18 would require enabling injection point support in src/test/subscription there, and v16 predates injection points entirely. That is more test infrastructure churn on stable branches than this fix warrants. Reported-by: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Author: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Co-authored-by: Bharath Rupireddy <bharath.rupireddyforpostgres@gmail.com> Reviewed-by: Ajin Cherian <itsajin@gmail.com> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Discussion: https://postgr.es/m/CAHg+QDcd_o3707Ey8c8b7HkE-t14g8c0tk8ME3ctywDsh3ut8g@mail.gmail.com Backpatch-through: 16 Branch ------ REL_19_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/4d9224a436f0e728b0b1bdd70e72c798bf4bbe98 Modified Files -------------- src/backend/commands/subscriptioncmds.c | 44 ++++++++++++++--- src/test/subscription/t/100_bugs.pl | 86 +++++++++++++++++++++++++++++++++ 2 files changed, 122 insertions(+), 8 deletions(-) ^ permalink raw reply [nested|flat] 5+ messages in thread
* pgsql: Fix crash in subscription refresh on concurrent relation drop. @ 2026-08-26 19:06 Masahiko Sawada <msawada@postgresql.org> 0 siblings, 0 replies; 5+ messages in thread From: Masahiko Sawada @ 2026-08-26 19:06 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix crash in subscription refresh on concurrent relation drop. Commit 46b4f5c11b0 made the logical replication origin checks quote the schema and relation names they interpolate into the query sent to the publisher. Those names can be NULL, which that commit overlooked. AlterSubscription_refresh() collects the OIDs of the relations already present in pg_subscription_rel and hands them to check_publications_origin_tables() and check_publications_origin_sequences(), which append the schema-qualified name of each one to the query so that already-subscribed relations are excluded from the check. The relations are never locked, so one of them can be dropped concurrently before its name is read, and get_rel_name() and get_namespace_name() return NULL. quote_literal_cstr() dereferences it and crashes the backend. This commit fixes this by skipping a relation whose name is no longer available. A dropped relation is not synchronized anyway, and the appended clauses only exclude relations from a check whose sole effect is a WARNING, so omitting one can at most produce a spurious WARNING. The window is reachable from ALTER SUBSCRIPTION ... REFRESH PUBLICATION and from SET, ADD and DROP PUBLICATION, which refresh by default, but only when copy_data is true and origin is none. Backpatch to v16 as commit 46b4f5c11b0 was back-patched that far. The sequence path exists only in v19 and later. The test is applied to v19 and later only. Adding it to v17 and v18 would require enabling injection point support in src/test/subscription there, and v16 predates injection points entirely. That is more test infrastructure churn on stable branches than this fix warrants. Reported-by: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Author: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Co-authored-by: Bharath Rupireddy <bharath.rupireddyforpostgres@gmail.com> Reviewed-by: Ajin Cherian <itsajin@gmail.com> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Discussion: https://postgr.es/m/CAHg+QDcd_o3707Ey8c8b7HkE-t14g8c0tk8ME3ctywDsh3ut8g@mail.gmail.com Backpatch-through: 16 Branch ------ REL_18_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/ec074c41efbd93ddc4b882c142c15c8d5b2ae6f8 Modified Files -------------- src/backend/commands/subscriptioncmds.c | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) ^ permalink raw reply [nested|flat] 5+ messages in thread
* pgsql: Fix crash in subscription refresh on concurrent relation drop. @ 2026-08-26 19:06 Masahiko Sawada <msawada@postgresql.org> 0 siblings, 0 replies; 5+ messages in thread From: Masahiko Sawada @ 2026-08-26 19:06 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix crash in subscription refresh on concurrent relation drop. Commit 46b4f5c11b0 made the logical replication origin checks quote the schema and relation names they interpolate into the query sent to the publisher. Those names can be NULL, which that commit overlooked. AlterSubscription_refresh() collects the OIDs of the relations already present in pg_subscription_rel and hands them to check_publications_origin_tables() and check_publications_origin_sequences(), which append the schema-qualified name of each one to the query so that already-subscribed relations are excluded from the check. The relations are never locked, so one of them can be dropped concurrently before its name is read, and get_rel_name() and get_namespace_name() return NULL. quote_literal_cstr() dereferences it and crashes the backend. This commit fixes this by skipping a relation whose name is no longer available. A dropped relation is not synchronized anyway, and the appended clauses only exclude relations from a check whose sole effect is a WARNING, so omitting one can at most produce a spurious WARNING. The window is reachable from ALTER SUBSCRIPTION ... REFRESH PUBLICATION and from SET, ADD and DROP PUBLICATION, which refresh by default, but only when copy_data is true and origin is none. Backpatch to v16 as commit 46b4f5c11b0 was back-patched that far. The sequence path exists only in v19 and later. The test is applied to v19 and later only. Adding it to v17 and v18 would require enabling injection point support in src/test/subscription there, and v16 predates injection points entirely. That is more test infrastructure churn on stable branches than this fix warrants. Reported-by: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Author: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Co-authored-by: Bharath Rupireddy <bharath.rupireddyforpostgres@gmail.com> Reviewed-by: Ajin Cherian <itsajin@gmail.com> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Discussion: https://postgr.es/m/CAHg+QDcd_o3707Ey8c8b7HkE-t14g8c0tk8ME3ctywDsh3ut8g@mail.gmail.com Backpatch-through: 16 Branch ------ REL_17_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/ebf7971dabac93558ebe0b1e47b4d665ac20c054 Modified Files -------------- src/backend/commands/subscriptioncmds.c | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) ^ permalink raw reply [nested|flat] 5+ messages in thread
* pgsql: Fix crash in subscription refresh on concurrent relation drop. @ 2026-08-26 19:06 Masahiko Sawada <msawada@postgresql.org> 0 siblings, 0 replies; 5+ messages in thread From: Masahiko Sawada @ 2026-08-26 19:06 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix crash in subscription refresh on concurrent relation drop. Commit 46b4f5c11b0 made the logical replication origin checks quote the schema and relation names they interpolate into the query sent to the publisher. Those names can be NULL, which that commit overlooked. AlterSubscription_refresh() collects the OIDs of the relations already present in pg_subscription_rel and hands them to check_publications_origin_tables() and check_publications_origin_sequences(), which append the schema-qualified name of each one to the query so that already-subscribed relations are excluded from the check. The relations are never locked, so one of them can be dropped concurrently before its name is read, and get_rel_name() and get_namespace_name() return NULL. quote_literal_cstr() dereferences it and crashes the backend. This commit fixes this by skipping a relation whose name is no longer available. A dropped relation is not synchronized anyway, and the appended clauses only exclude relations from a check whose sole effect is a WARNING, so omitting one can at most produce a spurious WARNING. The window is reachable from ALTER SUBSCRIPTION ... REFRESH PUBLICATION and from SET, ADD and DROP PUBLICATION, which refresh by default, but only when copy_data is true and origin is none. Backpatch to v16 as commit 46b4f5c11b0 was back-patched that far. The sequence path exists only in v19 and later. The test is applied to v19 and later only. Adding it to v17 and v18 would require enabling injection point support in src/test/subscription there, and v16 predates injection points entirely. That is more test infrastructure churn on stable branches than this fix warrants. Reported-by: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Author: SATYANARAYANA NARLAPURAM <satyanarlapuram@gmail.com> Co-authored-by: Bharath Rupireddy <bharath.rupireddyforpostgres@gmail.com> Reviewed-by: Ajin Cherian <itsajin@gmail.com> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Discussion: https://postgr.es/m/CAHg+QDcd_o3707Ey8c8b7HkE-t14g8c0tk8ME3ctywDsh3ut8g@mail.gmail.com Backpatch-through: 16 Branch ------ REL_16_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/ec8aaf845f4b7606ccf3b97247ebddd3548de917 Modified Files -------------- src/backend/commands/subscriptioncmds.c | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) ^ permalink raw reply [nested|flat] 5+ messages in thread
end of thread, other threads:[~2026-08-26 19:06 UTC | newest] Thread overview: 5+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2026-08-26 19:05 pgsql: Fix crash in subscription refresh on concurrent relation drop. Masahiko Sawada <msawada@postgresql.org> 2026-08-26 19:05 pgsql: Fix crash in subscription refresh on concurrent relation drop. Masahiko Sawada <msawada@postgresql.org> 2026-08-26 19:06 pgsql: Fix crash in subscription refresh on concurrent relation drop. Masahiko Sawada <msawada@postgresql.org> 2026-08-26 19:06 pgsql: Fix crash in subscription refresh on concurrent relation drop. Masahiko Sawada <msawada@postgresql.org> 2026-08-26 19:06 pgsql: Fix crash in subscription refresh on concurrent relation drop. Masahiko Sawada <msawada@postgresql.org>
This inbox is served by DDX for PostgreSQL; see mirroring instructions for how to clone and mirror all data and code used for this inbox