agora inbox for pgsql-committers@postgresql.org
help / color / mirror / Atom feedFrom: Daniel Gustafsson <dgustafsson@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Do not adopt data checksum state from another node during replay
Date: Mon, 14 Sep 2026 13:34:14 +0000
Message-ID: <E1x66p4-00000000I6H-2Hf6@gemulon.postgresql.org> (raw)
Do not adopt data checksum state from another node during replay
Offline data checksum changes with pg_checksums are local to one node,
but replay adopted the data checksum state carried by checkpoint record
unconditionally. After enabling checksums offline on only the primary,
a standby thus started verifying checksums it does not have. After an
offline change on a standby, the next replayed checkpoint silently
reverted the state.
To fix, make the control file track this node's state alone, and have
replay cross-check the replayed state against it instead of adopting
it, warning once per divergent value and reporting when the states
agree again. pg_control gains a watermark, normally the end LSN of
the newest XLOG2_CHECKSUMS record the node has written or applied,
and a flag marking that the state was last written by pg_checksums.
Recovery must never overwrite this state with a replayed one. The
control file is updated when all pages are flushed. This requires
a PG_CONTROL_VERSION bump.
Recovery from a base backup may be an exception to not adopting: its
control file was copied at an arbitrary moment, so the state carried
by the starting checkpoint is the one the WAL from there on was
Also document the offline procedure for replication setups.
Author: Zsolt Parragi <zsolt.parragi@percona.com>
Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reported-by: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
Discussion: https://postgr.es/m/anwm6UPxoVS41QA2@bdtpg
Backpatch-through: 19
Branch
------
master
Details
-------
https://git.postgresql.org/pg/commitdiff/b52a1c2c8a6acd4541a52e04cd14e3fcaffbeba0
Modified Files
--------------
doc/src/sgml/ref/pg_checksums.sgml | 87 +++-
doc/src/sgml/wal.sgml | 23 +
src/backend/access/transam/xlog.c | 555 ++++++++++++++++++---
src/backend/postmaster/datachecksum_state.c | 26 +-
src/backend/utils/activity/wait_event_names.txt | 1 +
src/bin/pg_checksums/pg_checksums.c | 10 +
src/bin/pg_controldata/pg_controldata.c | 4 +
src/bin/pg_resetwal/pg_resetwal.c | 7 +
src/bin/pg_rewind/pg_rewind.c | 35 +-
src/bin/pg_upgrade/controldata.c | 2 +-
src/include/catalog/pg_control.h | 29 +-
src/include/storage/lwlocklist.h | 1 +
src/test/modules/test_checksums/Makefile | 2 +-
src/test/modules/test_checksums/meson.build | 10 +
.../test_checksums/t/012_offline_standby.pl | 308 ++++++++++++
src/test/modules/test_checksums/t/013_rewind.pl | 201 ++++++++
src/test/modules/test_checksums/t/014_lockstep.pl | 182 +++++++
.../t/015_standby_crash_after_disable.pl | 135 +++++
.../test_checksums/t/016_promote_enable_crash.pl | 146 ++++++
.../test_checksums/t/017_restartpoint_race.pl | 151 ++++++
.../test_checksums/t/018_enable_crash_windows.pl | 518 +++++++++++++++++++
.../t/019_standby_shutdown_catchup.pl | 138 +++++
.../test_checksums/t/020_cascade_divergence.pl | 128 +++++
.../t/021_rewind_divergent_transitions.pl | 207 ++++++++
24 files changed, 2822 insertions(+), 84 deletions(-)
view thread (2+ messages) latest in thread
Message-ID: <E1x66p4-00000000I6H-2Hf6@gemulon.postgresql.org>
Permalink: ../E1x66p4-00000000I6H-2Hf6@gemulon.postgresql.org/
Also on: postgresql.org/message-id/E1x66p4-00000000I6H-2Hf6@gemulon.postgresql.org
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-committers@postgresql.org
Cc: dgustafsson@postgresql.org, pgsql-committers@lists.postgresql.org
Subject: Re: pgsql: Do not adopt data checksum state from another node during replay
In-Reply-To: <E1x66p4-00000000I6H-2Hf6@gemulon.postgresql.org>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox