agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
pgsql: Do not adopt data checksum state from another node during replay
2+ messages / 2 participants
[nested] [flat]

* pgsql: Do not adopt data checksum state from another node during replay
@ 2026-09-14 13:34 Daniel Gustafsson <dgustafsson@postgresql.org>
  2026-09-14 16:56 ` Re: pgsql: Do not adopt data checksum state from another node during replay Daniel Gustafsson <daniel@yesql.se>
  0 siblings, 1 reply; 2+ messages in thread

From: Daniel Gustafsson @ 2026-09-14 13:34 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Do not adopt data checksum state from another node during replay

Offline data checksum changes with pg_checksums are local to one node,
but replay adopted the data checksum state carried by checkpoint record
unconditionally.  After enabling checksums offline on only the primary,
a standby thus started verifying checksums it does not have.  After an
offline change on a standby, the next replayed checkpoint silently
reverted the state.

To fix, make the control file track this node's state alone, and have
replay cross-check the replayed state against it instead of adopting
it, warning once per divergent value and reporting when the states
agree again.  pg_control gains a watermark, normally the end LSN of
the newest XLOG2_CHECKSUMS record the node has written or applied,
and a flag marking that the state was last written by pg_checksums.
Recovery must never overwrite this state with a replayed one.  The
control file is updated when all pages are flushed.  This requires
a PG_CONTROL_VERSION bump.

Recovery from a base backup may be an exception to not adopting: its
control file was copied at an arbitrary moment, so the state carried
by the starting checkpoint is the one the WAL from there on was

Also document the offline procedure for replication setups.

Author: Zsolt Parragi <zsolt.parragi@percona.com>
Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reported-by: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
Discussion: https://postgr.es/m/anwm6UPxoVS41QA2@bdtpg
Backpatch-through: 19

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/b52a1c2c8a6acd4541a52e04cd14e3fcaffbeba0

Modified Files
--------------
doc/src/sgml/ref/pg_checksums.sgml                 |  87 +++-
doc/src/sgml/wal.sgml                              |  23 +
src/backend/access/transam/xlog.c                  | 555 ++++++++++++++++++---
src/backend/postmaster/datachecksum_state.c        |  26 +-
src/backend/utils/activity/wait_event_names.txt    |   1 +
src/bin/pg_checksums/pg_checksums.c                |  10 +
src/bin/pg_controldata/pg_controldata.c            |   4 +
src/bin/pg_resetwal/pg_resetwal.c                  |   7 +
src/bin/pg_rewind/pg_rewind.c                      |  35 +-
src/bin/pg_upgrade/controldata.c                   |   2 +-
src/include/catalog/pg_control.h                   |  29 +-
src/include/storage/lwlocklist.h                   |   1 +
src/test/modules/test_checksums/Makefile           |   2 +-
src/test/modules/test_checksums/meson.build        |  10 +
.../test_checksums/t/012_offline_standby.pl        | 308 ++++++++++++
src/test/modules/test_checksums/t/013_rewind.pl    | 201 ++++++++
src/test/modules/test_checksums/t/014_lockstep.pl  | 182 +++++++
.../t/015_standby_crash_after_disable.pl           | 135 +++++
.../test_checksums/t/016_promote_enable_crash.pl   | 146 ++++++
.../test_checksums/t/017_restartpoint_race.pl      | 151 ++++++
.../test_checksums/t/018_enable_crash_windows.pl   | 518 +++++++++++++++++++
.../t/019_standby_shutdown_catchup.pl              | 138 +++++
.../test_checksums/t/020_cascade_divergence.pl     | 128 +++++
.../t/021_rewind_divergent_transitions.pl          | 207 ++++++++
24 files changed, 2822 insertions(+), 84 deletions(-)



^ permalink  raw  reply  [nested|flat] 2+ messages in thread

* Re: pgsql: Do not adopt data checksum state from another node during replay
  2026-09-14 13:34 pgsql: Do not adopt data checksum state from another node during replay Daniel Gustafsson <dgustafsson@postgresql.org>
@ 2026-09-14 16:56 ` Daniel Gustafsson <daniel@yesql.se>
  0 siblings, 0 replies; 2+ messages in thread

From: Daniel Gustafsson @ 2026-09-14 16:56 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

> On 14 Sep 2026, at 15:34, Daniel Gustafsson <dgustafsson@postgresql.org> wrote:
> 
> Do not adopt data checksum state from another node during replay

I've seen the perl-check warning on the BF, I'm on it.

--
Daniel Gustafsson







^ permalink  raw  reply  [nested|flat] 2+ messages in thread


end of thread, other threads:[~2026-09-14 16:56 UTC | newest]

Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-09-14 13:34 pgsql: Do not adopt data checksum state from another node during replay Daniel Gustafsson <dgustafsson@postgresql.org>
2026-09-14 16:56 ` Daniel Gustafsson <daniel@yesql.se>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox