From: Tom Lane <tgl@sss.pgh.pa.us>
To: Fujii Masao <masao.fujii@oss.nttdata.com>
Cc: Hayato Kuroda (Fujitsu) <kuroda.hayato@fujitsu.com>
Cc: Andy Fan <zhihuifan1213@163.com>
Cc: 'Michael Paquier' <michael@paquier.xyz>
Cc: PostgreSQL Hackers <pgsql-hackers@postgresql.org>
Subject: Re: A assert failure when initdb with track_commit_timestamp=on
Date: Sat, 05 Jul 2025 14:00:07 -0400
Message-ID: <61810.1751738407@sss.pgh.pa.us> (raw)
In-Reply-To: <9093.1751736193@sss.pgh.pa.us>
References: <87plejmnpy.fsf@163.com>
<1f8f703d-72e8-4d05-ab16-ff0403a1d19d@oss.nttdata.com>
<aGXZL0oraweaENrF@paquier.xyz>
<OSCPR01MB14966207D000875CA4F4C9FEAF543A@OSCPR01MB14966.jpnprd01.prod.outlook.com>
<87o6u19z9w.fsf@163.com>
<3694f39a-7148-4197-91fe-25f3d01222b7@oss.nttdata.com>
<OSCPR01MB1496673E2FC58836331748DB6F542A@OSCPR01MB14966.jpnprd01.prod.outlook.com>
<efd05511-0b1f-4800-9eca-aadbf9bf5375@oss.nttdata.com>
<249358.1751643017@sss.pgh.pa.us>
<ac5d452d-7e9d-4643-b9e7-cb3423b04365@oss.nttdata.com>
<262595.1751649473@sss.pgh.pa.us>
<75d59502-b571-4df8-9269-fd07cee52dd4@oss.nttdata.com>
<9093.1751736193@sss.pgh.pa.us>
I wrote:
> Fujii Masao <masao.fujii@oss.nttdata.com> writes:
>> Or GUC ignore_system_indexes also should be treated in the same way
>> as transaction_timeout?
> Yes, I'd say we ought to mark that GUC as don't-accept-in-bootstrap
> too. I've not done any research about what other GUCs can break
> initdb, but now I'm starting to suspect there are several.
Here's a fleshed-out implementation of Hayato-san's idea. I've
not done anything about reverting 5a6c39b6d, nor have I done any
checks to see if there are other GUCs we ought to mark similarly.
(But at this point I'd be prepared to bet that there are.)
regards, tom lane
Attachments:
[text/x-diff] v1-disallow-setting-some-GUCs-in-bootstrap.patch (3.4K, ../61810.1751738407@sss.pgh.pa.us/2-v1-disallow-setting-some-GUCs-in-bootstrap.patch)
download | inline diff:diff --git a/src/backend/bootstrap/bootstrap.c b/src/backend/bootstrap/bootstrap.cindex fc8638c1b61..f6ca9e8632c 100644--- a/src/backend/bootstrap/bootstrap.c+++ b/src/backend/bootstrap/bootstrap.c@@ -213,6 +213,12 @@ BootstrapModeMain(int argc, char *argv[], bool check_only)
/* Set defaults, to be overridden by explicit options below */
InitializeGUCOptions();
+ /* Override ignore_system_indexes: we have no indexes during bootstrap */+ IgnoreSystemIndexes = true;++ /* Set bootstrap mode; note that this locks down values of some GUCs */+ SetProcessingMode(BootstrapProcessing);+
/* an initial --boot or --check should be present */
Assert(argc > 1
&& (strcmp(argv[1], "--boot") == 0
@@ -321,9 +327,6 @@ BootstrapModeMain(int argc, char *argv[], bool check_only)
CreateDataDirLockFile(false);
- SetProcessingMode(BootstrapProcessing);- IgnoreSystemIndexes = true;-
InitializeMaxBackends();
/*
diff --git a/src/backend/utils/misc/guc.c b/src/backend/utils/misc/guc.cindex 667df448732..215a20a1f06 100644--- a/src/backend/utils/misc/guc.c+++ b/src/backend/utils/misc/guc.c@@ -3464,6 +3464,15 @@ set_config_with_handle(const char *name, config_handle *handle,
return 0;
}
+ /*+ * Certain GUCs aren't safe to enable during bootstrap mode. Silently+ * ignore attempts to set them to non-default values.+ */+ if (unlikely(IsBootstrapProcessingMode()) &&+ (record->flags & GUC_NOT_IN_BOOTSTRAP) &&+ source > PGC_S_DYNAMIC_DEFAULT)+ changeVal = false;+
/*
* Check if the option can be set at this time. See guc.h for the precise
* rules.
diff --git a/src/backend/utils/misc/guc_tables.c b/src/backend/utils/misc/guc_tables.cindex 511dc32d519..064c6ba09e2 100644--- a/src/backend/utils/misc/guc_tables.c+++ b/src/backend/utils/misc/guc_tables.c@@ -1089,7 +1089,8 @@ struct config_bool ConfigureNamesBool[] =
{
{"track_commit_timestamp", PGC_POSTMASTER, REPLICATION_SENDING,
gettext_noop("Collects transaction commit time."),
- NULL+ NULL,+ GUC_NOT_IN_BOOTSTRAP
},
&track_commit_timestamp,
false,
@@ -1929,7 +1930,7 @@ struct config_bool ConfigureNamesBool[] =
gettext_noop("Disables reading from system indexes."),
gettext_noop("It does not prevent updating the indexes, so it is safe "
"to use. The worst consequence is slowness."),
- GUC_NOT_IN_SAMPLE+ GUC_NOT_IN_SAMPLE | GUC_NOT_IN_BOOTSTRAP
},
&IgnoreSystemIndexes,
false,
@@ -2763,7 +2764,7 @@ struct config_int ConfigureNamesInt[] =
{"transaction_timeout", PGC_USERSET, CLIENT_CONN_STATEMENT,
gettext_noop("Sets the maximum allowed duration of any transaction within a session (not a prepared transaction)."),
gettext_noop("0 disables the timeout."),
- GUC_UNIT_MS+ GUC_UNIT_MS | GUC_NOT_IN_BOOTSTRAP
},
&TransactionTimeout,
0, 0, INT_MAX,
diff --git a/src/include/utils/guc.h b/src/include/utils/guc.hindex f619100467d..0e7e97dabf0 100644--- a/src/include/utils/guc.h+++ b/src/include/utils/guc.h@@ -228,6 +228,7 @@ typedef enum
0x002000 /* can't set in PG_AUTOCONF_FILENAME */
#define GUC_RUNTIME_COMPUTED 0x004000 /* delay processing in 'postgres -C' */
#define GUC_ALLOW_IN_PARALLEL 0x008000 /* allow setting in parallel mode */
+#define GUC_NOT_IN_BOOTSTRAP 0x010000 /* can't set in bootstrap mode */
#define GUC_UNIT_KB 0x01000000 /* value is in kilobytes */
#define GUC_UNIT_BLOCKS 0x02000000 /* value is in blocks */
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-hackers@postgresql.org
Cc: tgl@sss.pgh.pa.us, masao.fujii@oss.nttdata.com, kuroda.hayato@fujitsu.com, zhihuifan1213@163.com, michael@paquier.xyz
Subject: Re: A assert failure when initdb with track_commit_timestamp=on
In-Reply-To: <61810.1751738407@sss.pgh.pa.us>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox