Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x4yUK-007XM5-12 for pgsql-hackers@arkaria.postgresql.org; Fri, 11 Sep 2026 10:28:08 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1x4yUI-00E2VM-2G for pgsql-hackers@arkaria.postgresql.org; Fri, 11 Sep 2026 10:28:06 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x4yQp-00DsK0-3B for pgsql-hackers@lists.postgresql.org; Fri, 11 Sep 2026 10:24:32 +0000 Received: from mail-wm2-x10.google.com ([2a00:1450:4864:31::10]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1x4xmv-000000047pN-1Dcp for pgsql-hackers@lists.postgresql.org; Fri, 11 Sep 2026 09:43:21 +0000 Received: by mail-wm2-x10.google.com with SMTP id 5b1f17b1804b1-49d097b4939so3191395e9.0 for ; Fri, 11 Sep 2026 02:43:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cybertec.at; s=google; t=1789119796; x=1789724596; darn=lists.postgresql.org; h=message-id:date:content-transfer-encoding:content-type:mime-version :comments:references:in-reply-to:subject:cc:to:from:from:to:cc :subject:date:message-id:reply-to:content-type; bh=7ZwZ2At9mMkJt5HfQ/YGf7D8WqHL90pm7YF/u9I/YzI=; b=K9cHWzap5VAe/iSQ4vXedHy0k0d/ajjCfeXhwlwqDhJDHHr5i6U4Leyj9yK8DF+5YE xuFT4E0ELpOXM9TTh6vs/cILN4k1RshiTdwfl3WyN2fuaQ3ZNRl903FecWToU9gyNpUE y/MDUl6KJtueQWqZ9Eq5Mn77THT7zwfvTiVLsjy0/VVT0tTYLeujxTuzzbD56EXMLmpf vEDPZl567ma7SwQ4gRxIeb0M8q4xfrFWTK94c5bvI4UyMNIxe8g0JJxYUQ5luX1cjG9G UjDcWkA4n5fl8AmBqea5setGRSIkGfQIFadPVTvajKUfoDMYNA9Asaow+8m113VkWGt8 38pw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789119796; x=1789724596; h=message-id:date:content-transfer-encoding:content-type:mime-version :comments:references:in-reply-to:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=7ZwZ2At9mMkJt5HfQ/YGf7D8WqHL90pm7YF/u9I/YzI=; b=mJeSPOkIlizjtnHCrhvlHUAxpn7zUvqYwLXNgE0sl+2LodOEm9+64/M4dnKi5KnP3m 74RdSZi+BIh0N5ho0xEsagNmVbgjtTNe+hb5yeEjcR1YhbP8uGh9u8nty8daZENKI3LY I3ToNkY+Kzk4qbZ0omEKhuQlYC4UJ5OQ7W7HENEcZo4z6wJsGmEf23+05+OIW98vAfVD EO50xmem2yhKt7PAfm8r9wjOz4TLXkmC6HYYnd8Y1i3s1+T+T/6MhoteXEWqHKreye94 cKRpYDqHYOZxEesanmH3q3vy9zOyswZqQ4YzVsEAxOPgOBRIrmplGPqFZeQONnDQCx2c 4XpA== X-Forwarded-Encrypted: i=1; AKwUvBzSCxzdMV/ZDVZQwYnI/wxoZTeFkeOBCv3Fq7H4x5aJgrBUjB6rrGHDfseRcYcnu9E33pcUYeyhQqQEYmJ6@lists.postgresql.org X-Gm-Message-State: AFuF++nEZl0dm/lqJuIQL3faXNCM/IYOHnLqeXytAjOm7Hlk5hjT/s4n 9By0oXN9+s6Xlm4Z0Mj/w/k8/UGGiSywDxCMHz0rAFI/tg3YocNKk+ehwsL4uCsZy5Y= X-Gm-Gg: AYBFou2+1gj/bjxbS1qoVgWioGWHWdp3N+GNyTWmYE/v8bQVMEF5kytBGnfxGar5oih RnLIrIhMGZTOHa0ibK12uRN+WNosmH2e0zcKeV15BCtnEM8OuSz0Fj8j87Mut2LpEw8WVCInRi5 IE86nwMadwGGLDCEitYNYmlQljQnIWnlYZILAomOboiYPoNoePiMl0W9pbou/8lcpe/yG2HNvFW Iy0IxczJIKEkpw9C/9yGq2HQ4DuqHX1GWZhUPBmeVTtBCmKY++3JJkrW4WEQJ+/H3klvlK9tf+C /2wCHgf213ZgTjvjE5WfMCsiL0bDoklnIrVeTYVbXOW3ViAvnUoNLp0/t7Kqj0Fcdft9NTw4L+b xrT4/dRcPLYn+5Gr5Sf7icUWt+OceUUPpJrkVKdt9vVtAM6QQUC92VWO0km54L465A/3Tn8swGw lMQZXk4xSv2pV2DGgAXLig1fWDwOHwfuUm2b4RQmyBLeQ1JBv5eqJFtTkqeYHVpXTfP2L0UG96B rMCOLODoimd X-Received: by 2002:a05:600c:34ca:b0:499:9240:9a1c with SMTP id 5b1f17b1804b1-49e619a09d3mr36987485e9.15.1789119796262; Fri, 11 Sep 2026 02:43:16 -0700 (PDT) Received: from localhost (109-81-170-190.rct.o2.cz. [109.81.170.190]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-486eb32e6f1sm4680778f8f.6.2026.09.11.02.43.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 02:43:15 -0700 (PDT) From: Antonin Houska To: alvherre@kurilemu.de cc: Noah Misch , Andres Freund , pgsql-hackers@lists.postgresql.org, Mihail Nikalayeu Subject: Re: Race conditions in logical decoding In-reply-to: References: Comments: In-reply-to =?us-ascii?Q?=3D=3Futf-8=3FQ=3F=3DC3=3D81lvaro=3F=3D?= Herrera message dated "Fri, 11 Sep 2026 11:03:14 +0200." X-Mailer: MH-E 8.6+git; nmh 1.8; GNU Emacs 28.3 MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Date: Fri, 11 Sep 2026 11:43:15 +0200 Message-ID: <13367.1789119795@localhost> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk =C3=81lvaro Herrera wrote: > On 2026-Sep-10, Noah Misch wrote: >=20 > > On Fri, Aug 21, 2026 at 08:16:02PM +0200, =C3=81lvaro Herrera wrote: > > > So, what do you think of the attached? > >=20 > > I see $SUBJECT lost open item status because released versions have the= same > > defect. However, REPACK (CONCURRENTLY) increases the importance of $SU= BJECT > > and other logical replication data loss causes. In v18, one can recrea= te the > > replica or run integrity checks before a cutover. REPACK (CONCURRENTLY) > > automates the chain: one command starts replication, waits for consiste= ncy, > > and deletes the last known good copy. > >=20 > > If v19 ships without a fix for $SUBJECT, I think REPACK (CONCURRENTLY) = docs > > need to warn about the situation. How do you see it? >=20 > I think this kind of bug makes logical decoding effectively unusable, > because you can never predict when this bug is going to hit and > therefore when you're going to silently lose data. I agree that REPACK > (CONCURRENTLY) having automated the potential for data loss is severe. > I doubt it'd make sense to release it with this bug. So my intention is > to get it fixed before release. Actually even the impact on logical replication is worse than described above. As I pointed out at the beginning of this thread, even the data on t= he publisher can get corrupted: if visibility checks work incorrectly, hint bi= ts can be set incorrectly as well. The isolation tester spec file in [1] expla= ins the problem more in detail. I'm not sure if such corruption was already reported - the race is probably pretty rare - but it's possible. As for REPACK (CONCURRENTLY), I think it makes the corruption more likely to happen because it's an additional use c= ase for the snapshot built by the logical decoding system. [1] https://www.postgresql.org/message-id/flat/aqPBWUkBniZcxRl-%40alvherre.= pgsql#828c33540c873236a693bfe84f6e8fac --=20 Antonin Houska Web: https://www.cybertec-postgresql.com