agora inbox for pgsql-hackers@postgresql.org  
help / color / mirror / Atom feed
Avoid orphaned objects dependencies, take 3
93+ messages / 9 participants
[nested] [flat]

* Avoid orphaned objects dependencies, take 3
@ 2024-04-22 08:45 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-04-22 08:45 UTC (permalink / raw)
  To: pgsql-hackers@lists.postgresql.org

Hi,

This new thread is a follow-up of [1] and [2].

Problem description:

We have occasionally observed objects having an orphaned dependency, the 
most common case we have seen is functions not linked to any namespaces.

Examples to produce such orphaned dependencies:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

A patch has been initially proposed to fix this particular 
(function-to-namespace) dependency (see [1]), but there could be much 
more scenarios (like the function-to-datatype one highlighted by Gilles 
in [1] that could lead to a function having an invalid parameter datatype).

As Tom said there are dozens more cases that would need to be 
considered, and a global approach to avoid those race conditions should 
be considered instead.

A first global approach attempt has been proposed in [2] making use of a dirty
snapshot when recording the dependency. But this approach appeared to be "scary"
and it was still failing to close some race conditions (see [2] for details).

Then, Tom proposed another approach in [2] which is that "creation DDL will have
to take a lock on each referenced object that'd conflict with a lock taken by
DROP".

This is what the attached patch is trying to achieve.

It does the following:

1) A new lock (that conflicts with a lock taken by DROP) has been put in place
when the dependencies are being recorded.

Thanks to it, the drop schema in scenario 2 would be locked (resulting in an
error should session 1 committs).

2) After locking the object while recording the dependency, the patch checks
that the object still exists.

Thanks to it, session 2 in scenario 1 would be locked and would report an error
once session 1 committs (that would not be the case should session 1 abort the
transaction).

The patch also adds a few tests for some dependency cases (that would currently
produce orphaned objects):

- schema and function (as the above scenarios)
- function and type
- table and type (which is I think problematic enough, as involving a table into
the game, to fix this stuff as a whole).

[1]: https://www.postgresql.org/message-id/flat/a4f55089-7cbd-fe5d-a9bb-19adc6418ae9@darold.net#9af5cdaa9...
[2]: https://www.postgresql.org/message-id/flat/8369ff70-0e31-f194-2954-787f4d9e21dd%40amazon.com

Please note that I'm not used to with this area of the code so that the patch
might not take the option proposed by Tom the "right" way.

Adding the patch to the July CF.

Looking forward to your feedback,

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v1-0001-Avoid-orphaned-objects-dependencies.patch (13.7K, ../../ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal/2-v1-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 6798e85b0679dfccfa665007b06d9f1a0e39e0c6 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v1] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after locking the object, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- function and type
- table and type
---
 src/backend/catalog/dependency.c              | 42 ++++++++++++++
 src/backend/catalog/objectaddress.c           | 57 +++++++++++++++++++
 src/backend/catalog/pg_depend.c               |  6 ++
 src/include/catalog/dependency.h              |  1 +
 src/include/catalog/objectaddress.h           |  1 +
 src/test/modules/Makefile                     |  1 +
 src/test/modules/meson.build                  |  1 +
 .../test_dependencies_locks/.gitignore        |  3 +
 .../modules/test_dependencies_locks/Makefile  | 14 +++++
 .../expected/test_dependencies_locks.out      | 49 ++++++++++++++++
 .../test_dependencies_locks/meson.build       | 12 ++++
 .../specs/test_dependencies_locks.spec        | 39 +++++++++++++
 12 files changed, 226 insertions(+)
  34.6% src/backend/catalog/
  32.7% src/test/modules/test_dependencies_locks/expected/
  20.7% src/test/modules/test_dependencies_locks/specs/
   9.2% src/test/modules/test_dependencies_locks/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..2251145e3b 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,48 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/*
+	 * If we don't get a description then there is no need to worry about this
+	 * object as it is certainly not in the progress of being dropped.
+	 */
+	if (!object_description)
+		return;
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+		ereport(ERROR, errmsg("%s does not exist", object_description));
+
+	pfree(object_description);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..8cb1adae89 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	int			cache;
+	HeapTuple	tuple;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index f85a898de8..f7b0ad3a42 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -106,6 +106,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency.
+		 */
+		depLockAndCheckObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index ec654010d4..8915548711 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -94,6 +94,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..56f746264b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/modules/Makefile b/src/test/modules/Makefile
index 256799f520..75f357100f 100644
--- a/src/test/modules/Makefile
+++ b/src/test/modules/Makefile
@@ -17,6 +17,7 @@ SUBDIRS = \
 		  test_copy_callbacks \
 		  test_custom_rmgrs \
 		  test_ddl_deparse \
+		  test_dependencies_locks \
 		  test_dsa \
 		  test_dsm_registry \
 		  test_extensions \
diff --git a/src/test/modules/meson.build b/src/test/modules/meson.build
index d8fe059d23..60305dcccd 100644
--- a/src/test/modules/meson.build
+++ b/src/test/modules/meson.build
@@ -16,6 +16,7 @@ subdir('test_bloomfilter')
 subdir('test_copy_callbacks')
 subdir('test_custom_rmgrs')
 subdir('test_ddl_deparse')
+subdir('test_dependencies_locks')
 subdir('test_dsa')
 subdir('test_dsm_registry')
 subdir('test_extensions')
diff --git a/src/test/modules/test_dependencies_locks/.gitignore b/src/test/modules/test_dependencies_locks/.gitignore
new file mode 100644
index 0000000000..bf000faac4
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/.gitignore
@@ -0,0 +1,3 @@
+# Generated subdirectories
+/log/
+/output_iso
diff --git a/src/test/modules/test_dependencies_locks/Makefile b/src/test/modules/test_dependencies_locks/Makefile
new file mode 100644
index 0000000000..7491048380
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/Makefile
@@ -0,0 +1,14 @@
+# src/test/modules/test_dependencies_locks/Makefile
+
+ISOLATION = test_dependencies_locks
+
+ifdef USE_PGXS
+PG_CONFIG = pg_config
+PGXS := $(shell $(PG_CONFIG) --pgxs)
+include $(PGXS)
+else
+subdir = src/test/modules/test_dependencies_locks
+top_builddir = ../../../..
+include $(top_builddir)/src/Makefile.global
+include $(top_srcdir)/contrib/contrib-global.mk
+endif
diff --git a/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..d0980f77d5
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
@@ -0,0 +1,49 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_type s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_type: CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_type: CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_type: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
diff --git a/src/test/modules/test_dependencies_locks/meson.build b/src/test/modules/test_dependencies_locks/meson.build
new file mode 100644
index 0000000000..92a978ab93
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/meson.build
@@ -0,0 +1,12 @@
+# Copyright (c) 2024, PostgreSQL Global Development Group
+
+tests += {
+  'name': 'test_dependencies_locks',
+  'sd': meson.current_source_dir(),
+  'bd': meson.current_build_dir(),
+  'isolation': {
+    'specs': [
+      'test_dependencies_locks',
+    ],
+  },
+}
diff --git a/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..fd15bd2a78
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
@@ -0,0 +1,39 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS footype(num foo);
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_type" { CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_commit" { COMMIT; }
+
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+permutation "s1_begin" "s1_create_function_with_type" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_type" "s2_commit"
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-04-22 10:00 ` Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Alexander Lakhin @ 2024-04-22 10:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; pgsql-hackers@lists.postgresql.org

Hi Bertrand,

22.04.2024 11:45, Bertrand Drouvot wrote:
> Hi,
>
> This new thread is a follow-up of [1] and [2].
>
> Problem description:
>
> We have occasionally observed objects having an orphaned dependency, the
> most common case we have seen is functions not linked to any namespaces.
>
> ...
>
> Looking forward to your feedback,

This have reminded me of bug #17182 [1].
Unfortunately, with the patch applied, the following script:

for ((i=1;i<=100;i++)); do
   ( { for ((n=1;n<=20;n++)); do echo "DROP SCHEMA s;"; done } | psql ) >psql1.log 2>&1 &
   echo "
CREATE SCHEMA s;
CREATE FUNCTION s.func1() RETURNS int LANGUAGE SQL AS 'SELECT 1;';
CREATE FUNCTION s.func2() RETURNS int LANGUAGE SQL AS 'SELECT 2;';
CREATE FUNCTION s.func3() RETURNS int LANGUAGE SQL AS 'SELECT 3;';
CREATE FUNCTION s.func4() RETURNS int LANGUAGE SQL AS 'SELECT 4;';
CREATE FUNCTION s.func5() RETURNS int LANGUAGE SQL AS 'SELECT 5;';
   "  | psql >psql2.log 2>&1 &
   wait
   psql -c "DROP SCHEMA s CASCADE" >psql3.log
done
echo "
SELECT pg_identify_object('pg_proc'::regclass, pp.oid, 0), pp.oid FROM pg_proc pp
   LEFT JOIN pg_namespace pn ON pp.pronamespace = pn.oid WHERE pn.oid IS NULL" | psql

still ends with:
server closed the connection unexpectedly
         This probably means the server terminated abnormally
         before or while processing the request.

2024-04-22 09:54:39.171 UTC|||662633dc.152bbc|LOG:  server process (PID 1388378) was terminated by signal 11: 
Segmentation fault
2024-04-22 09:54:39.171 UTC|||662633dc.152bbc|DETAIL:  Failed process was running: SELECT 
pg_identify_object('pg_proc'::regclass, pp.oid, 0), pp.oid FROM pg_proc pp
       LEFT JOIN pg_namespace pn ON pp.pronamespace = pn.oid WHERE pn.oid IS NULL

[1] https://www.postgresql.org/message-id/flat/17182-a6baa001dd1784be%40postgresql.org

Best regards,
Alexander





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
@ 2024-04-22 10:52   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-04-22 10:52 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

On Mon, Apr 22, 2024 at 01:00:00PM +0300, Alexander Lakhin wrote:
> Hi Bertrand,
> 
> 22.04.2024 11:45, Bertrand Drouvot wrote:
> > Hi,
> > 
> > This new thread is a follow-up of [1] and [2].
> > 
> > Problem description:
> > 
> > We have occasionally observed objects having an orphaned dependency, the
> > most common case we have seen is functions not linked to any namespaces.
> > 
> > ...
> > 
> > Looking forward to your feedback,
> 
> This have reminded me of bug #17182 [1].

Thanks for the link to the bug!

> Unfortunately, with the patch applied, the following script:
> 
> for ((i=1;i<=100;i++)); do
>   ( { for ((n=1;n<=20;n++)); do echo "DROP SCHEMA s;"; done } | psql ) >psql1.log 2>&1 &
>   echo "
> CREATE SCHEMA s;
> CREATE FUNCTION s.func1() RETURNS int LANGUAGE SQL AS 'SELECT 1;';
> CREATE FUNCTION s.func2() RETURNS int LANGUAGE SQL AS 'SELECT 2;';
> CREATE FUNCTION s.func3() RETURNS int LANGUAGE SQL AS 'SELECT 3;';
> CREATE FUNCTION s.func4() RETURNS int LANGUAGE SQL AS 'SELECT 4;';
> CREATE FUNCTION s.func5() RETURNS int LANGUAGE SQL AS 'SELECT 5;';
>   "  | psql >psql2.log 2>&1 &
>   wait
>   psql -c "DROP SCHEMA s CASCADE" >psql3.log
> done
> echo "
> SELECT pg_identify_object('pg_proc'::regclass, pp.oid, 0), pp.oid FROM pg_proc pp
>   LEFT JOIN pg_namespace pn ON pp.pronamespace = pn.oid WHERE pn.oid IS NULL" | psql
> 
> still ends with:
> server closed the connection unexpectedly
>         This probably means the server terminated abnormally
>         before or while processing the request.
> 
> 2024-04-22 09:54:39.171 UTC|||662633dc.152bbc|LOG:  server process (PID
> 1388378) was terminated by signal 11: Segmentation fault
> 2024-04-22 09:54:39.171 UTC|||662633dc.152bbc|DETAIL:  Failed process was
> running: SELECT pg_identify_object('pg_proc'::regclass, pp.oid, 0), pp.oid
> FROM pg_proc pp
>       LEFT JOIN pg_namespace pn ON pp.pronamespace = pn.oid WHERE pn.oid IS NULL
> 

Thanks for sharing the script.

That's weird, I just launched it several times with the patch applied and I'm not
able to see the seg fault (while I can see it constently failing on the master
branch).

Are you 100% sure you tested it against a binary with the patch applied?

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-04-22 12:00     ` Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Alexander Lakhin @ 2024-04-22 12:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

22.04.2024 13:52, Bertrand Drouvot wrote:
>
> That's weird, I just launched it several times with the patch applied and I'm not
> able to see the seg fault (while I can see it constently failing on the master
> branch).
>
> Are you 100% sure you tested it against a binary with the patch applied?
>

Yes, at least I can't see what I'm doing wrong. Please try my
self-contained script attached.

Best regards,
Alexander
#!/bin/bash

git reset --hard HEAD; git clean -dfx >/dev/null
wget https://www.postgresql.org/message-id/attachment/159685/v1-0001-Avoid-orphaned-objects-dependencies....
git apply v1-0001-Avoid-orphaned-objects-dependencies.patch || exit 1
CPPFLAGS="-Og" ./configure --enable-debug --enable-cassert -q && make -j8 -s && TESTS="test_setup" make -s check-tests

PGROOT=`pwd`/tmp_install
export PGDATA=`pwd`/tmpdb

export PATH="$PGROOT/usr/local/pgsql/bin:$PATH"
export LD_LIBRARY_PATH="$PGROOT/usr/local/pgsql/lib"

initdb >initdb.log 2>&1

export PGPORT=55432
echo "
port=$PGPORT
fsync = off
" > $PGDATA/postgresql.auto.conf

pg_ctl -l server.log start
export PGDATABASE=regression

createdb regression

for ((i=1;i<=300;i++)); do
  ( { for ((n=1;n<=20;n++)); do echo "DROP SCHEMA s;"; done } | psql ) >psql1.log 2>&1 & 
  echo "
CREATE SCHEMA s;
CREATE FUNCTION s.func1() RETURNS int LANGUAGE SQL AS 'SELECT 1;';
CREATE FUNCTION s.func2() RETURNS int LANGUAGE SQL AS 'SELECT 2;';
CREATE FUNCTION s.func3() RETURNS int LANGUAGE SQL AS 'SELECT 3;';
CREATE FUNCTION s.func4() RETURNS int LANGUAGE SQL AS 'SELECT 4;';
CREATE FUNCTION s.func5() RETURNS int LANGUAGE SQL AS 'SELECT 5;';
  "  | psql >psql2.log 2>&1 &
  wait
  psql -c "DROP SCHEMA s CASCADE" >psql3.log
done
echo "
SELECT pg_identify_object('pg_proc'::regclass, pp.oid, 0), pp.oid FROM pg_proc pp
  LEFT JOIN pg_namespace pn ON pp.pronamespace = pn.oid WHERE pn.oid IS NULL" | psql

pg_ctl -w -t 5 -D "$PGDATA" stop


Attachments:

  [text/plain] repro-17182.sh.txt (1.4K, ../../a0e850b9-31c6-86cd-351d-6b8a7a1d6bf7@gmail.com/2-repro-17182.sh.txt)
  download | inline:
#!/bin/bash

git reset --hard HEAD; git clean -dfx >/dev/null
wget https://www.postgresql.org/message-id/attachment/159685/v1-0001-Avoid-orphaned-objects-dependencies.patch
git apply v1-0001-Avoid-orphaned-objects-dependencies.patch || exit 1
CPPFLAGS="-Og" ./configure --enable-debug --enable-cassert -q && make -j8 -s && TESTS="test_setup" make -s check-tests

PGROOT=`pwd`/tmp_install
export PGDATA=`pwd`/tmpdb

export PATH="$PGROOT/usr/local/pgsql/bin:$PATH"
export LD_LIBRARY_PATH="$PGROOT/usr/local/pgsql/lib"

initdb >initdb.log 2>&1

export PGPORT=55432
echo "
port=$PGPORT
fsync = off
" > $PGDATA/postgresql.auto.conf

pg_ctl -l server.log start
export PGDATABASE=regression

createdb regression

for ((i=1;i<=300;i++)); do
  ( { for ((n=1;n<=20;n++)); do echo "DROP SCHEMA s;"; done } | psql ) >psql1.log 2>&1 & 
  echo "
CREATE SCHEMA s;
CREATE FUNCTION s.func1() RETURNS int LANGUAGE SQL AS 'SELECT 1;';
CREATE FUNCTION s.func2() RETURNS int LANGUAGE SQL AS 'SELECT 2;';
CREATE FUNCTION s.func3() RETURNS int LANGUAGE SQL AS 'SELECT 3;';
CREATE FUNCTION s.func4() RETURNS int LANGUAGE SQL AS 'SELECT 4;';
CREATE FUNCTION s.func5() RETURNS int LANGUAGE SQL AS 'SELECT 5;';
  "  | psql >psql2.log 2>&1 &
  wait
  psql -c "DROP SCHEMA s CASCADE" >psql3.log
done
echo "
SELECT pg_identify_object('pg_proc'::regclass, pp.oid, 0), pp.oid FROM pg_proc pp
  LEFT JOIN pg_namespace pn ON pp.pronamespace = pn.oid WHERE pn.oid IS NULL" | psql

pg_ctl -w -t 5 -D "$PGDATA" stop

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
@ 2024-04-23 04:59       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-04-23 04:59 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

On Mon, Apr 22, 2024 at 03:00:00PM +0300, Alexander Lakhin wrote:
> 22.04.2024 13:52, Bertrand Drouvot wrote:
> > 
> > That's weird, I just launched it several times with the patch applied and I'm not
> > able to see the seg fault (while I can see it constently failing on the master
> > branch).
> > 
> > Are you 100% sure you tested it against a binary with the patch applied?
> > 
> 
> Yes, at least I can't see what I'm doing wrong. Please try my
> self-contained script attached.

Thanks for sharing your script!

Yeah your script ensures the patch is applied before the repro is executed.

I do confirm that I can also see the issue with the patch applied (but I had to
launch multiple attempts, while on master one attempt is enough).

I'll have a look.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-04-23 16:20         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-04-23 16:20 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

On Tue, Apr 23, 2024 at 04:59:09AM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Mon, Apr 22, 2024 at 03:00:00PM +0300, Alexander Lakhin wrote:
> > 22.04.2024 13:52, Bertrand Drouvot wrote:
> > > 
> > > That's weird, I just launched it several times with the patch applied and I'm not
> > > able to see the seg fault (while I can see it constently failing on the master
> > > branch).
> > > 
> > > Are you 100% sure you tested it against a binary with the patch applied?
> > > 
> > 
> > Yes, at least I can't see what I'm doing wrong. Please try my
> > self-contained script attached.
> 
> Thanks for sharing your script!
> 
> Yeah your script ensures the patch is applied before the repro is executed.
> 
> I do confirm that I can also see the issue with the patch applied (but I had to
> launch multiple attempts, while on master one attempt is enough).
> 
> I'll have a look.

Please find attached v2 that should not produce the issue anymore (I launched a
lot of attempts without any issues). v1 was not strong enough as it was not
always checking for the dependent object existence. v2 now always checks if the
object still exists after the additional lock acquisition attempt while recording
the dependency.

I still need to think about v2 but in the meantime could you please also give
v2 a try on you side?

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v2-0001-Avoid-orphaned-objects-dependencies.patch (14.2K, ../../Ziff3vGRKv1LUjY7@ip-10-97-1-34.eu-west-3.compute.internal/2-v2-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From f80fdfc32e791463555aa318f26ff5e7363ac3ac Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v2] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after locking the object, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- function and type
- table and type
---
 src/backend/catalog/dependency.c              | 48 +++++++++++++
 src/backend/catalog/objectaddress.c           | 70 +++++++++++++++++++
 src/backend/catalog/pg_depend.c               |  6 ++
 src/include/catalog/dependency.h              |  1 +
 src/include/catalog/objectaddress.h           |  1 +
 src/test/modules/Makefile                     |  1 +
 src/test/modules/meson.build                  |  1 +
 .../test_dependencies_locks/.gitignore        |  3 +
 .../modules/test_dependencies_locks/Makefile  | 14 ++++
 .../expected/test_dependencies_locks.out      | 49 +++++++++++++
 .../test_dependencies_locks/meson.build       | 12 ++++
 .../specs/test_dependencies_locks.spec        | 39 +++++++++++
 12 files changed, 245 insertions(+)
  38.1% src/backend/catalog/
  30.7% src/test/modules/test_dependencies_locks/expected/
  19.5% src/test/modules/test_dependencies_locks/specs/
   8.7% src/test/modules/test_dependencies_locks/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..e3b66025dd 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,54 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it, so bypass the syscache
+		 * lookup and use a dirty snaphot instead.
+		 */
+		if (!ObjectByIdExist(object, true))
+		{
+			if(object_description)
+				ereport(ERROR, errmsg("%s does not exist", object_description));
+			else
+				ereport(ERROR, errmsg("a dependent object does not exist"));
+		}
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..c2b873dd81 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,76 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot)
+{
+	HeapTuple	tuple;
+	int			cache = -1;
+	const ObjectPropertyType *property;
+
+	if (!use_dirty_snapshot)
+	{
+		property = get_object_property_data(address->classId);
+
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		SnapshotData DirtySnapshot;
+		Snapshot	snapshot;
+
+		if (use_dirty_snapshot)
+		{
+			InitDirtySnapshot(DirtySnapshot);
+			snapshot = &DirtySnapshot;
+		}
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  snapshot, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index f85a898de8..6bb218f5dd 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -106,6 +106,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency. XXX - Should we do so only for DEPENDENCY_NORMAL?
+		 */
+		depLockAndCheckObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index ec654010d4..8915548711 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -94,6 +94,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..04891abcc1 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/modules/Makefile b/src/test/modules/Makefile
index 256799f520..75f357100f 100644
--- a/src/test/modules/Makefile
+++ b/src/test/modules/Makefile
@@ -17,6 +17,7 @@ SUBDIRS = \
 		  test_copy_callbacks \
 		  test_custom_rmgrs \
 		  test_ddl_deparse \
+		  test_dependencies_locks \
 		  test_dsa \
 		  test_dsm_registry \
 		  test_extensions \
diff --git a/src/test/modules/meson.build b/src/test/modules/meson.build
index d8fe059d23..60305dcccd 100644
--- a/src/test/modules/meson.build
+++ b/src/test/modules/meson.build
@@ -16,6 +16,7 @@ subdir('test_bloomfilter')
 subdir('test_copy_callbacks')
 subdir('test_custom_rmgrs')
 subdir('test_ddl_deparse')
+subdir('test_dependencies_locks')
 subdir('test_dsa')
 subdir('test_dsm_registry')
 subdir('test_extensions')
diff --git a/src/test/modules/test_dependencies_locks/.gitignore b/src/test/modules/test_dependencies_locks/.gitignore
new file mode 100644
index 0000000000..bf000faac4
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/.gitignore
@@ -0,0 +1,3 @@
+# Generated subdirectories
+/log/
+/output_iso
diff --git a/src/test/modules/test_dependencies_locks/Makefile b/src/test/modules/test_dependencies_locks/Makefile
new file mode 100644
index 0000000000..7491048380
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/Makefile
@@ -0,0 +1,14 @@
+# src/test/modules/test_dependencies_locks/Makefile
+
+ISOLATION = test_dependencies_locks
+
+ifdef USE_PGXS
+PG_CONFIG = pg_config
+PGXS := $(shell $(PG_CONFIG) --pgxs)
+include $(PGXS)
+else
+subdir = src/test/modules/test_dependencies_locks
+top_builddir = ../../../..
+include $(top_builddir)/src/Makefile.global
+include $(top_srcdir)/contrib/contrib-global.mk
+endif
diff --git a/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..d0980f77d5
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
@@ -0,0 +1,49 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_type s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_type: CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_type: CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_type: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
diff --git a/src/test/modules/test_dependencies_locks/meson.build b/src/test/modules/test_dependencies_locks/meson.build
new file mode 100644
index 0000000000..92a978ab93
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/meson.build
@@ -0,0 +1,12 @@
+# Copyright (c) 2024, PostgreSQL Global Development Group
+
+tests += {
+  'name': 'test_dependencies_locks',
+  'sd': meson.current_source_dir(),
+  'bd': meson.current_build_dir(),
+  'isolation': {
+    'specs': [
+      'test_dependencies_locks',
+    ],
+  },
+}
diff --git a/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..fd15bd2a78
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
@@ -0,0 +1,39 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS footype(num foo);
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_type" { CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_commit" { COMMIT; }
+
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+permutation "s1_begin" "s1_create_function_with_type" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_type" "s2_commit"
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-04-24 08:38           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-04-24 08:38 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

On Tue, Apr 23, 2024 at 04:20:46PM +0000, Bertrand Drouvot wrote:
> Please find attached v2 that should not produce the issue anymore (I launched a
> lot of attempts without any issues). v1 was not strong enough as it was not
> always checking for the dependent object existence. v2 now always checks if the
> object still exists after the additional lock acquisition attempt while recording
> the dependency.
> 
> I still need to think about v2 but in the meantime could you please also give
> v2 a try on you side?

I gave more thought to v2 and the approach seems reasonable to me. Basically what
it does is that in case the object is already dropped before we take the new lock
(while recording the dependency) then the error message is a "generic" one (means
it does not provide the description of the "already" dropped object). I think it
makes sense to write the patch that way by abandoning the patch's ambition to
tell the description of the dropped object in all the cases.

Of course, I would be happy to hear others thought about it.

Please find v3 attached (which is v2 with more comments).

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v3-0001-Avoid-orphaned-objects-dependencies.patch (14.5K, ../../ZijE6UBCo02U2TXJ@ip-10-97-1-34.eu-west-3.compute.internal/2-v3-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 32945912ceddad6b171fd8b345adefa4432af357 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v3] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after locking the object, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- function and type
- table and type
---
 src/backend/catalog/dependency.c              | 54 ++++++++++++++
 src/backend/catalog/objectaddress.c           | 70 +++++++++++++++++++
 src/backend/catalog/pg_depend.c               |  6 ++
 src/include/catalog/dependency.h              |  1 +
 src/include/catalog/objectaddress.h           |  1 +
 src/test/modules/Makefile                     |  1 +
 src/test/modules/meson.build                  |  1 +
 .../test_dependencies_locks/.gitignore        |  3 +
 .../modules/test_dependencies_locks/Makefile  | 14 ++++
 .../expected/test_dependencies_locks.out      | 49 +++++++++++++
 .../test_dependencies_locks/meson.build       | 12 ++++
 .../specs/test_dependencies_locks.spec        | 39 +++++++++++
 12 files changed, 251 insertions(+)
  40.5% src/backend/catalog/
  29.6% src/test/modules/test_dependencies_locks/expected/
  18.7% src/test/modules/test_dependencies_locks/specs/
   8.3% src/test/modules/test_dependencies_locks/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..a49357bbe2 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,60 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it (for example creating
+		 * a composite type while creating a relation), so bypass the syscache
+		 * lookup and use a dirty snaphot instead to cover this scenario.
+		 */
+		if (!ObjectByIdExist(object, true))
+		{
+			/*
+			 * If the object has been dropped before we get a chance to get
+			 * its description, then emit a generic error message. That looks
+			 * like a good compromise over extra complexity.
+			 */
+			if (object_description)
+				ereport(ERROR, errmsg("%s does not exist", object_description));
+			else
+				ereport(ERROR, errmsg("a dependent object does not exist"));
+		}
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..c2b873dd81 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,76 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot)
+{
+	HeapTuple	tuple;
+	int			cache = -1;
+	const ObjectPropertyType *property;
+
+	if (!use_dirty_snapshot)
+	{
+		property = get_object_property_data(address->classId);
+
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		SnapshotData DirtySnapshot;
+		Snapshot	snapshot;
+
+		if (use_dirty_snapshot)
+		{
+			InitDirtySnapshot(DirtySnapshot);
+			snapshot = &DirtySnapshot;
+		}
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  snapshot, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index f85a898de8..6bb218f5dd 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -106,6 +106,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency. XXX - Should we do so only for DEPENDENCY_NORMAL?
+		 */
+		depLockAndCheckObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index ec654010d4..8915548711 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -94,6 +94,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..04891abcc1 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/modules/Makefile b/src/test/modules/Makefile
index 256799f520..75f357100f 100644
--- a/src/test/modules/Makefile
+++ b/src/test/modules/Makefile
@@ -17,6 +17,7 @@ SUBDIRS = \
 		  test_copy_callbacks \
 		  test_custom_rmgrs \
 		  test_ddl_deparse \
+		  test_dependencies_locks \
 		  test_dsa \
 		  test_dsm_registry \
 		  test_extensions \
diff --git a/src/test/modules/meson.build b/src/test/modules/meson.build
index d8fe059d23..60305dcccd 100644
--- a/src/test/modules/meson.build
+++ b/src/test/modules/meson.build
@@ -16,6 +16,7 @@ subdir('test_bloomfilter')
 subdir('test_copy_callbacks')
 subdir('test_custom_rmgrs')
 subdir('test_ddl_deparse')
+subdir('test_dependencies_locks')
 subdir('test_dsa')
 subdir('test_dsm_registry')
 subdir('test_extensions')
diff --git a/src/test/modules/test_dependencies_locks/.gitignore b/src/test/modules/test_dependencies_locks/.gitignore
new file mode 100644
index 0000000000..bf000faac4
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/.gitignore
@@ -0,0 +1,3 @@
+# Generated subdirectories
+/log/
+/output_iso
diff --git a/src/test/modules/test_dependencies_locks/Makefile b/src/test/modules/test_dependencies_locks/Makefile
new file mode 100644
index 0000000000..7491048380
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/Makefile
@@ -0,0 +1,14 @@
+# src/test/modules/test_dependencies_locks/Makefile
+
+ISOLATION = test_dependencies_locks
+
+ifdef USE_PGXS
+PG_CONFIG = pg_config
+PGXS := $(shell $(PG_CONFIG) --pgxs)
+include $(PGXS)
+else
+subdir = src/test/modules/test_dependencies_locks
+top_builddir = ../../../..
+include $(top_builddir)/src/Makefile.global
+include $(top_srcdir)/contrib/contrib-global.mk
+endif
diff --git a/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..d0980f77d5
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
@@ -0,0 +1,49 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_type s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_type: CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_type: CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_type: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
diff --git a/src/test/modules/test_dependencies_locks/meson.build b/src/test/modules/test_dependencies_locks/meson.build
new file mode 100644
index 0000000000..92a978ab93
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/meson.build
@@ -0,0 +1,12 @@
+# Copyright (c) 2024, PostgreSQL Global Development Group
+
+tests += {
+  'name': 'test_dependencies_locks',
+  'sd': meson.current_source_dir(),
+  'bd': meson.current_build_dir(),
+  'isolation': {
+    'specs': [
+      'test_dependencies_locks',
+    ],
+  },
+}
diff --git a/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..fd15bd2a78
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
@@ -0,0 +1,39 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS footype(num foo);
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_type" { CREATE FUNCTION footype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_commit" { COMMIT; }
+
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+permutation "s1_begin" "s1_create_function_with_type" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_type" "s2_commit"
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-04-24 12:00             ` Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Alexander Lakhin @ 2024-04-24 12:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi Bertrand,

24.04.2024 11:38, Bertrand Drouvot wrote:
>> Please find attached v2 that should not produce the issue anymore (I launched a
>> lot of attempts without any issues). v1 was not strong enough as it was not
>> always checking for the dependent object existence. v2 now always checks if the
>> object still exists after the additional lock acquisition attempt while recording
>> the dependency.
>>
>> I still need to think about v2 but in the meantime could you please also give
>> v2 a try on you side?
> I gave more thought to v2 and the approach seems reasonable to me. Basically what
> it does is that in case the object is already dropped before we take the new lock
> (while recording the dependency) then the error message is a "generic" one (means
> it does not provide the description of the "already" dropped object). I think it
> makes sense to write the patch that way by abandoning the patch's ambition to
> tell the description of the dropped object in all the cases.
>
> Of course, I would be happy to hear others thought about it.
>
> Please find v3 attached (which is v2 with more comments).

Thank you for the improved version!

I can confirm that it fixes that case.
I've also tested other cases that fail on master (most of them also fail
with v1), please try/look at the attached script. (There could be other
broken-dependency cases, of course, but I think I've covered all the
representative ones.)

All tested cases work correctly with v3 applied — I couldn't get broken
dependencies, though concurrent create/drop operations can still produce
the "cache lookup failed" error, which is probably okay, except that it is
an INTERNAL_ERROR, which assumed to be not easily triggered by users.

Best regards,
Alexander
if [ "$1" == "function-schema" ]; then
res=1
for ((i=1;i<=300;i++)); do
  ( { for ((n=1;n<=20;n++)); do echo "DROP SCHEMA s;"; done } | psql ) >psql1.log 2>&1 & 
  echo "
CREATE SCHEMA s;
CREATE FUNCTION s.func1() RETURNS int LANGUAGE SQL AS 'SELECT 1;';
CREATE FUNCTION s.func2() RETURNS int LANGUAGE SQL AS 'SELECT 2;';
CREATE FUNCTION s.func3() RETURNS int LANGUAGE SQL AS 'SELECT 3;';
CREATE FUNCTION s.func4() RETURNS int LANGUAGE SQL AS 'SELECT 4;';
CREATE FUNCTION s.func5() RETURNS int LANGUAGE SQL AS 'SELECT 5;';
  "  | psql >psql2.log 2>&1 &
  wait
  psql -c "DROP SCHEMA s CASCADE" >psql3.log 2>&1
done
echo "
SELECT pg_identify_object('pg_proc'::regclass, pp.oid, 0), pp.oid FROM pg_proc pp
  LEFT JOIN pg_namespace pn ON pp.pronamespace = pn.oid WHERE pn.oid IS NULL" | psql
sleep 1
grep 'was terminated' server.log || res=0
fi


if [ "$1" == "function-function" ]; then
res=1
for ((i=1;i<=1000;i++)); do
( { for ((n=1;n<=20;n++)); do echo "DROP FUNCTION f();"; done } | psql ) >psql1.log 2>&1 &
( echo "
CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
CREATE FUNCTION f1() RETURNS int LANGUAGE SQL RETURN f() + 1;
CREATE FUNCTION f2() RETURNS int LANGUAGE SQL RETURN f() + 2;
CREATE FUNCTION f3() RETURNS int LANGUAGE SQL RETURN f() + 3;
CREATE FUNCTION f4() RETURNS int LANGUAGE SQL RETURN f() + 4;
CREATE FUNCTION f5() RETURNS int LANGUAGE SQL RETURN f() + 5;
" | psql ) >psql2.log 2>&1 &
wait
echo "ALTER FUNCTION f1() RENAME TO f01; SELECT f01()" | psql 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }

psql -c "DROP FUNCTION f() CASCADE" >psql3.log 2>&1
done

grep -A2 'cache lookup failed' server.log || res=0
fi


if [ "$1" == "function-rettype" ]; then
res=0
for ((i=1;i<=5000;i++)); do
( echo "
CREATE DOMAIN id AS int;
CREATE FUNCTION f1() RETURNS id LANGUAGE SQL RETURN 1;
CREATE FUNCTION f2() RETURNS id LANGUAGE SQL RETURN 2;
CREATE FUNCTION f3() RETURNS id LANGUAGE SQL RETURN 3;
CREATE FUNCTION f4() RETURNS id LANGUAGE SQL RETURN 4;
CREATE FUNCTION f5() RETURNS id LANGUAGE SQL RETURN 5;
" | psql ) >psql1.log 2>&1 &
( echo "SELECT pg_sleep(random() / 100); DROP DOMAIN id"  | psql ) >psql2.log 2>&1 &
wait

psql -c "SELECT f1()" 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
psql -c "DROP DOMAIN id CASCADE" >psql3.log 2>&1
done

[ $res == 1 ] && psql -c "SELECT pn.oid, proname, pronamespace, proowner, prolang, prorettype FROM pg_proc pp INNER JOIN pg_namespace pn ON (pp.pronamespace = pn.oid) WHERE pn.nspname='public'"
fi


if [ "$1" == "function-argtype" ]; then
res=0
for ((i=1;i<=5000;i++)); do
( echo "
CREATE DOMAIN id AS int;
CREATE FUNCTION f1(i id) RETURNS int LANGUAGE SQL RETURN 1;
CREATE FUNCTION f2(i id) RETURNS int LANGUAGE SQL RETURN 2;
CREATE FUNCTION f3(i id) RETURNS int LANGUAGE SQL RETURN 3;
CREATE FUNCTION f4(i id) RETURNS int LANGUAGE SQL RETURN 4;
CREATE FUNCTION f5(i id) RETURNS int LANGUAGE SQL RETURN 5;
" | psql ) >psql1.log 2>&1 &
( echo "SELECT pg_sleep(random() / 1000); DROP DOMAIN id" | psql ) >psql2.log 2>&1 &
wait

psql -c "SELECT f1(1)" 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
psql -q -c "DROP DOMAIN id CASCADE" >/dev/null 2>&1
done

grep -A1 'cache lookup failed' server.log || res=0
fi


if [ "$1" == "domain-domain" ]; then
res=0
for ((i=1;i<=30;i++)); do
{ echo "CREATE DOMAIN id AS int;"; for ((d=1;d<100;d++)); do echo "CREATE DOMAIN id$d AS id;"; done; echo "DROP DOMAIN id CASCADE;"; } | psql >psql0.log 2>&1
{ for ((n=1;n<=100;n++)); do echo "CREATE DOMAIN id AS int;"; for ((d=1;d<100;d++)); do echo "CREATE DOMAIN id$d AS id;"; done; echo "DROP DOMAIN id CASCADE;"; done; } | ON_ERROR_STOP=1 psql >psql1.log 2>&1 &
{ for ((n=1;n<=100;n++)); do echo "SELECT pg_sleep(random() / 100); DROP DOMAIN id;"; done; } | psql >psql2.log 2>&1 &
wait
  
psql -c "CREATE TABLE t1(i id1)" 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
done
grep -A1 'cache lookup failed' server.log
psql -c "\\dD+ i*"
fi


if [ "$1" == "table-trigger" ]; then
res=1
for ((i=1;i<=100;i++)); do
psql -c "DROP TABLE IF EXISTS t"
psql -c "CREATE TABLE t(i int, c text)"
( { for ((n=1;n<=30;n++)); do echo "DROP FUNCTION trigger_func();"; done } | psql ) >>psql1.log 2>&1 &
( echo "
CREATE FUNCTION trigger_func() RETURNS trigger LANGUAGE plpgsql AS '
BEGIN
    RAISE NOTICE ''trigger_func(%) called: action = %, when = %, level = %'', TG_ARGV[0], TG_OP, TG_WHEN, TG_LEVEL;
    RETURN NULL;
END;';
CREATE TRIGGER modified_c1 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
CREATE TRIGGER modified_c2 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
CREATE TRIGGER modified_c3 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
CREATE TRIGGER modified_c4 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
CREATE TRIGGER modified_c5 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
" | psql ) >>psql2.log 2>&1 &
wait
psql -c "DROP FUNCTION trigger_func() CASCADE" >psql3.log 2>&1

psql -c "INSERT INTO t VALUES(1, 'a')"
psql -c "UPDATE t SET c='b'" 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
done

grep -A2 'cache lookup failed' server.log || res=0
fi


if [ "$1" == "table-coltype" ]; then
res=0
numclients=20
for ((i=1;i<=50;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "SELECT pg_sleep(random() / 2000); DROP DOMAIN id_$c RESTRICT" | psql >psql1-$c.log 2>&1 &
  echo "
CREATE DOMAIN id_$c int;
CREATE TABLE tbl_$c (i id_$c);
  " | psql >psql2-$c.log 2>&1 &
done
wait
for ((c=1;c<=numclients;c++)); do
  echo "SELECT * FROM tbl_$c" | psql 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
  echo "DROP DOMAIN id_$c CASCADE; DROP TABLE tbl_$c" | psql >psql3-$c.log 2>&1
done
[ $res == 1 ] && break;
done
grep -A2 'cache lookup failed' server.log
fi


if [ "$1" == "type-shelltype" ]; then
res=0
numclients=40
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "DROP FUNCTION IF EXISTS xint8in_$c, xint8out_$c CASCADE" | psql >psql0-$c.log 2>&1
done
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE TYPE xint8_$c;
CREATE FUNCTION xint8in_$c(cstring) RETURNS xint8_$c IMMUTABLE STRICT LANGUAGE INTERNAL AS 'int8in';
CREATE FUNCTION xint8out_$c(xint8_$c) RETURNS cstring IMMUTABLE STRICT LANGUAGE INTERNAL AS 'int8out';
CREATE TYPE xint8_$c(input = xint8in_$c, output = xint8out_$c, like = int8);
  " | psql >psql1-$c.log 2>&1 &
  echo "SELECT pg_sleep(random() / 1000); DROP TYPE xint8_$c CASCADE;" | psql >psql2-$c.log 2>&1 &
done
wait
grep 'TRAP' server.log && { echo "on iteration $i"; res=1; break; }
done
fi


if [ "$1" == "type-schema" ]; then
res=0
numclients=20
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE SCHEMA s_$c;
CREATE DOMAIN s_$c.dom_$c int4;
CREATE TABLE tbl_$c (i dom_$c);
  " | psql >psql1-$c.log 2>&1 &
  echo "DROP SCHEMA s_$c RESTRICT" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
  echo "DROP SCHEMA s_$c CASCADE" | psql >psql3-$c.log 2>&1
done
done
fi


if [ "$1" == "ts_template-schema" ]; then
res=0
numclients=20
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE SCHEMA s_$c;
CREATE TEXT SEARCH TEMPLATE s_$c.tst_$c(lexize=dsimple_lexize);
  " | psql >psql1-$c.log 2>&1 &
  echo "DROP SCHEMA s_$c RESTRICT;" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
  echo "DROP SCHEMA s_$c CASCADE;" | psql >psql3-$c.log 2>&1
done
done
fi


if [ "$1" == "cast-schema" ]; then
res=0
numclients=20
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE SCHEMA s_$c;
CREATE DOMAIN s_$c.dom_$c int4;
CREATE TABLE tbl_$c (i dom_$c);
  " | psql >psql1-$c.log 2>&1 &
  echo "DROP SCHEMA s_$c RESTRICT;" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
  echo "DROP SCHEMA s_$c CASCADE;" | psql >psql3-$c.log 2>&1
done
done
fi


if [ "$1" == "cast-function" ]; then
res=0
echo "
CREATE TYPE tt;
CREATE FUNCTION tt_in(cstring) RETURNS tt AS 'textin' LANGUAGE internal STRICT IMMUTABLE;
CREATE FUNCTION tt_out(tt) RETURNS cstring AS 'textout' LANGUAGE internal STRICT IMMUTABLE;

CREATE TYPE tt (internallength = variable, input = tt_in, output = tt_out, alignment = int4);
" | psql

numclients=2
for ((n=1;n<=500;n++)); do
  for ((i=1;i<=$numclients;i++)); do
cat << 'EOF' | psql >psql-$i.log 2>&1 &
DROP CAST (int4 AS tt);
CREATE FUNCTION cf(int4) RETURNS tt LANGUAGE SQL AS
  $$ SELECT ($1::text)::tt; $$;
CREATE CAST (int4 AS tt) WITH FUNCTION cf(int4) AS IMPLICIT;
DROP FUNCTION cf(int4) CASCADE;
EOF
  done
  wait
  echo "SELECT 1234::int4::tt;" | psql 2>&1 | grep 'cache lookup failed for function'
  pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
done
fi


if [ "$1" == "server-fdw_wrapper" ]; then
res=0
numclients=20
for ((i=1;i<=200;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE FOREIGN DATA WRAPPER fdw_wrapper_$c;
CREATE SERVER tst_$c FOREIGN DATA WRAPPER fdw_wrapper_$c;
  " | psql >psql1-$c.log 2>&1 &
  echo "DROP FOREIGN DATA WRAPPER fdw_wrapper_$c RESTRICT;" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
  echo "DROP FOREIGN DATA WRAPPER fdw_wrapper_$c CASCADE;" | psql >psql3-$c.log 2>&1
done
done
fi


Attachments:

  [text/plain] test-broken-deps.sh.txt (9.5K, ../../62310067-6dc4-97ab-6724-7d3602b5056d@gmail.com/2-test-broken-deps.sh.txt)
  download | inline:
if [ "$1" == "function-schema" ]; then
res=1
for ((i=1;i<=300;i++)); do
  ( { for ((n=1;n<=20;n++)); do echo "DROP SCHEMA s;"; done } | psql ) >psql1.log 2>&1 & 
  echo "
CREATE SCHEMA s;
CREATE FUNCTION s.func1() RETURNS int LANGUAGE SQL AS 'SELECT 1;';
CREATE FUNCTION s.func2() RETURNS int LANGUAGE SQL AS 'SELECT 2;';
CREATE FUNCTION s.func3() RETURNS int LANGUAGE SQL AS 'SELECT 3;';
CREATE FUNCTION s.func4() RETURNS int LANGUAGE SQL AS 'SELECT 4;';
CREATE FUNCTION s.func5() RETURNS int LANGUAGE SQL AS 'SELECT 5;';
  "  | psql >psql2.log 2>&1 &
  wait
  psql -c "DROP SCHEMA s CASCADE" >psql3.log 2>&1
done
echo "
SELECT pg_identify_object('pg_proc'::regclass, pp.oid, 0), pp.oid FROM pg_proc pp
  LEFT JOIN pg_namespace pn ON pp.pronamespace = pn.oid WHERE pn.oid IS NULL" | psql
sleep 1
grep 'was terminated' server.log || res=0
fi


if [ "$1" == "function-function" ]; then
res=1
for ((i=1;i<=1000;i++)); do
( { for ((n=1;n<=20;n++)); do echo "DROP FUNCTION f();"; done } | psql ) >psql1.log 2>&1 &
( echo "
CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
CREATE FUNCTION f1() RETURNS int LANGUAGE SQL RETURN f() + 1;
CREATE FUNCTION f2() RETURNS int LANGUAGE SQL RETURN f() + 2;
CREATE FUNCTION f3() RETURNS int LANGUAGE SQL RETURN f() + 3;
CREATE FUNCTION f4() RETURNS int LANGUAGE SQL RETURN f() + 4;
CREATE FUNCTION f5() RETURNS int LANGUAGE SQL RETURN f() + 5;
" | psql ) >psql2.log 2>&1 &
wait
echo "ALTER FUNCTION f1() RENAME TO f01; SELECT f01()" | psql 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }

psql -c "DROP FUNCTION f() CASCADE" >psql3.log 2>&1
done

grep -A2 'cache lookup failed' server.log || res=0
fi


if [ "$1" == "function-rettype" ]; then
res=0
for ((i=1;i<=5000;i++)); do
( echo "
CREATE DOMAIN id AS int;
CREATE FUNCTION f1() RETURNS id LANGUAGE SQL RETURN 1;
CREATE FUNCTION f2() RETURNS id LANGUAGE SQL RETURN 2;
CREATE FUNCTION f3() RETURNS id LANGUAGE SQL RETURN 3;
CREATE FUNCTION f4() RETURNS id LANGUAGE SQL RETURN 4;
CREATE FUNCTION f5() RETURNS id LANGUAGE SQL RETURN 5;
" | psql ) >psql1.log 2>&1 &
( echo "SELECT pg_sleep(random() / 100); DROP DOMAIN id"  | psql ) >psql2.log 2>&1 &
wait

psql -c "SELECT f1()" 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
psql -c "DROP DOMAIN id CASCADE" >psql3.log 2>&1
done

[ $res == 1 ] && psql -c "SELECT pn.oid, proname, pronamespace, proowner, prolang, prorettype FROM pg_proc pp INNER JOIN pg_namespace pn ON (pp.pronamespace = pn.oid) WHERE pn.nspname='public'"
fi


if [ "$1" == "function-argtype" ]; then
res=0
for ((i=1;i<=5000;i++)); do
( echo "
CREATE DOMAIN id AS int;
CREATE FUNCTION f1(i id) RETURNS int LANGUAGE SQL RETURN 1;
CREATE FUNCTION f2(i id) RETURNS int LANGUAGE SQL RETURN 2;
CREATE FUNCTION f3(i id) RETURNS int LANGUAGE SQL RETURN 3;
CREATE FUNCTION f4(i id) RETURNS int LANGUAGE SQL RETURN 4;
CREATE FUNCTION f5(i id) RETURNS int LANGUAGE SQL RETURN 5;
" | psql ) >psql1.log 2>&1 &
( echo "SELECT pg_sleep(random() / 1000); DROP DOMAIN id" | psql ) >psql2.log 2>&1 &
wait

psql -c "SELECT f1(1)" 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
psql -q -c "DROP DOMAIN id CASCADE" >/dev/null 2>&1
done

grep -A1 'cache lookup failed' server.log || res=0
fi


if [ "$1" == "domain-domain" ]; then
res=0
for ((i=1;i<=30;i++)); do
{ echo "CREATE DOMAIN id AS int;"; for ((d=1;d<100;d++)); do echo "CREATE DOMAIN id$d AS id;"; done; echo "DROP DOMAIN id CASCADE;"; } | psql >psql0.log 2>&1
{ for ((n=1;n<=100;n++)); do echo "CREATE DOMAIN id AS int;"; for ((d=1;d<100;d++)); do echo "CREATE DOMAIN id$d AS id;"; done; echo "DROP DOMAIN id CASCADE;"; done; } | ON_ERROR_STOP=1 psql >psql1.log 2>&1 &
{ for ((n=1;n<=100;n++)); do echo "SELECT pg_sleep(random() / 100); DROP DOMAIN id;"; done; } | psql >psql2.log 2>&1 &
wait
  
psql -c "CREATE TABLE t1(i id1)" 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
done
grep -A1 'cache lookup failed' server.log
psql -c "\\dD+ i*"
fi


if [ "$1" == "table-trigger" ]; then
res=1
for ((i=1;i<=100;i++)); do
psql -c "DROP TABLE IF EXISTS t"
psql -c "CREATE TABLE t(i int, c text)"
( { for ((n=1;n<=30;n++)); do echo "DROP FUNCTION trigger_func();"; done } | psql ) >>psql1.log 2>&1 &
( echo "
CREATE FUNCTION trigger_func() RETURNS trigger LANGUAGE plpgsql AS '
BEGIN
    RAISE NOTICE ''trigger_func(%) called: action = %, when = %, level = %'', TG_ARGV[0], TG_OP, TG_WHEN, TG_LEVEL;
    RETURN NULL;
END;';
CREATE TRIGGER modified_c1 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
CREATE TRIGGER modified_c2 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
CREATE TRIGGER modified_c3 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
CREATE TRIGGER modified_c4 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
CREATE TRIGGER modified_c5 BEFORE UPDATE OF c ON t
FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
" | psql ) >>psql2.log 2>&1 &
wait
psql -c "DROP FUNCTION trigger_func() CASCADE" >psql3.log 2>&1

psql -c "INSERT INTO t VALUES(1, 'a')"
psql -c "UPDATE t SET c='b'" 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
done

grep -A2 'cache lookup failed' server.log || res=0
fi


if [ "$1" == "table-coltype" ]; then
res=0
numclients=20
for ((i=1;i<=50;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "SELECT pg_sleep(random() / 2000); DROP DOMAIN id_$c RESTRICT" | psql >psql1-$c.log 2>&1 &
  echo "
CREATE DOMAIN id_$c int;
CREATE TABLE tbl_$c (i id_$c);
  " | psql >psql2-$c.log 2>&1 &
done
wait
for ((c=1;c<=numclients;c++)); do
  echo "SELECT * FROM tbl_$c" | psql 2>&1 | grep 'cache lookup failed' && { echo "on iteration $i"; res=1; break; }
  echo "DROP DOMAIN id_$c CASCADE; DROP TABLE tbl_$c" | psql >psql3-$c.log 2>&1
done
[ $res == 1 ] && break;
done
grep -A2 'cache lookup failed' server.log
fi


if [ "$1" == "type-shelltype" ]; then
res=0
numclients=40
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "DROP FUNCTION IF EXISTS xint8in_$c, xint8out_$c CASCADE" | psql >psql0-$c.log 2>&1
done
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE TYPE xint8_$c;
CREATE FUNCTION xint8in_$c(cstring) RETURNS xint8_$c IMMUTABLE STRICT LANGUAGE INTERNAL AS 'int8in';
CREATE FUNCTION xint8out_$c(xint8_$c) RETURNS cstring IMMUTABLE STRICT LANGUAGE INTERNAL AS 'int8out';
CREATE TYPE xint8_$c(input = xint8in_$c, output = xint8out_$c, like = int8);
  " | psql >psql1-$c.log 2>&1 &
  echo "SELECT pg_sleep(random() / 1000); DROP TYPE xint8_$c CASCADE;" | psql >psql2-$c.log 2>&1 &
done
wait
grep 'TRAP' server.log && { echo "on iteration $i"; res=1; break; }
done
fi


if [ "$1" == "type-schema" ]; then
res=0
numclients=20
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE SCHEMA s_$c;
CREATE DOMAIN s_$c.dom_$c int4;
CREATE TABLE tbl_$c (i dom_$c);
  " | psql >psql1-$c.log 2>&1 &
  echo "DROP SCHEMA s_$c RESTRICT" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
  echo "DROP SCHEMA s_$c CASCADE" | psql >psql3-$c.log 2>&1
done
done
fi


if [ "$1" == "ts_template-schema" ]; then
res=0
numclients=20
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE SCHEMA s_$c;
CREATE TEXT SEARCH TEMPLATE s_$c.tst_$c(lexize=dsimple_lexize);
  " | psql >psql1-$c.log 2>&1 &
  echo "DROP SCHEMA s_$c RESTRICT;" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
  echo "DROP SCHEMA s_$c CASCADE;" | psql >psql3-$c.log 2>&1
done
done
fi


if [ "$1" == "cast-schema" ]; then
res=0
numclients=20
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE SCHEMA s_$c;
CREATE DOMAIN s_$c.dom_$c int4;
CREATE TABLE tbl_$c (i dom_$c);
  " | psql >psql1-$c.log 2>&1 &
  echo "DROP SCHEMA s_$c RESTRICT;" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
  echo "DROP SCHEMA s_$c CASCADE;" | psql >psql3-$c.log 2>&1
done
done
fi


if [ "$1" == "cast-function" ]; then
res=0
echo "
CREATE TYPE tt;
CREATE FUNCTION tt_in(cstring) RETURNS tt AS 'textin' LANGUAGE internal STRICT IMMUTABLE;
CREATE FUNCTION tt_out(tt) RETURNS cstring AS 'textout' LANGUAGE internal STRICT IMMUTABLE;

CREATE TYPE tt (internallength = variable, input = tt_in, output = tt_out, alignment = int4);
" | psql

numclients=2
for ((n=1;n<=500;n++)); do
  for ((i=1;i<=$numclients;i++)); do
cat << 'EOF' | psql >psql-$i.log 2>&1 &
DROP CAST (int4 AS tt);
CREATE FUNCTION cf(int4) RETURNS tt LANGUAGE SQL AS
  $$ SELECT ($1::text)::tt; $$;
CREATE CAST (int4 AS tt) WITH FUNCTION cf(int4) AS IMPLICIT;
DROP FUNCTION cf(int4) CASCADE;
EOF
  done
  wait
  echo "SELECT 1234::int4::tt;" | psql 2>&1 | grep 'cache lookup failed for function'
  pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
done
fi


if [ "$1" == "server-fdw_wrapper" ]; then
res=0
numclients=20
for ((i=1;i<=200;i++)); do
for ((c=1;c<=numclients;c++)); do
  echo "
CREATE FOREIGN DATA WRAPPER fdw_wrapper_$c;
CREATE SERVER tst_$c FOREIGN DATA WRAPPER fdw_wrapper_$c;
  " | psql >psql1-$c.log 2>&1 &
  echo "DROP FOREIGN DATA WRAPPER fdw_wrapper_$c RESTRICT;" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
  echo "DROP FOREIGN DATA WRAPPER fdw_wrapper_$c CASCADE;" | psql >psql3-$c.log 2>&1
done
done
fi

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
@ 2024-04-25 05:00               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-04-25 05:00 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

On Wed, Apr 24, 2024 at 03:00:00PM +0300, Alexander Lakhin wrote:
> 24.04.2024 11:38, Bertrand Drouvot wrote:
> > I gave more thought to v2 and the approach seems reasonable to me. Basically what
> > it does is that in case the object is already dropped before we take the new lock
> > (while recording the dependency) then the error message is a "generic" one (means
> > it does not provide the description of the "already" dropped object). I think it
> > makes sense to write the patch that way by abandoning the patch's ambition to
> > tell the description of the dropped object in all the cases.
> > 
> > Of course, I would be happy to hear others thought about it.
> > 
> > Please find v3 attached (which is v2 with more comments).
> 
> Thank you for the improved version!
> 
> I can confirm that it fixes that case.

Great, thanks for the test!

> I've also tested other cases that fail on master (most of them also fail
> with v1), please try/look at the attached script.

Thanks for all those tests!

> (There could be other broken-dependency cases, of course, but I think I've
> covered all the representative ones.)

Agree. Furthermore the way the patch is written should be agnostic to the
object's kind that are part of the dependency. Having said that, that does not
hurt to add more tests in this patch, so v4 attached adds some of your tests (
that would fail on the master branch without the patch applied).

The way the tests are written in the patch are less "racy" that when triggered
with your script. Indeed, I think that in the patch the dependent object can not
be removed before the new lock is taken when recording the dependency. We may
want to add injection points in the game if we feel the need.

> All tested cases work correctly with v3 applied —

Yeah, same on my side, I did run them too and did not find any issues.

> I couldn't get broken
> dependencies,

Same here.

> though concurrent create/drop operations can still produce
> the "cache lookup failed" error, which is probably okay, except that it is
> an INTERNAL_ERROR, which assumed to be not easily triggered by users.

I did not see any of those "cache lookup failed" during my testing with/without
your script. During which test(s) did you see those with v3 applied?

Attached v4, simply adding more tests to v3.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v4-0001-Avoid-orphaned-objects-dependencies.patch (19.8K, ../../ZinjZmaMEEkOSfZ0@ip-10-97-1-34.eu-west-3.compute.internal/2-v4-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From a9b34955fab0351b7b5a7ba6eb36f199f5a5822c Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v4] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/dependency.c              |  54 +++++++++
 src/backend/catalog/objectaddress.c           |  70 +++++++++++
 src/backend/catalog/pg_depend.c               |   6 +
 src/include/catalog/dependency.h              |   1 +
 src/include/catalog/objectaddress.h           |   1 +
 src/test/modules/Makefile                     |   1 +
 src/test/modules/meson.build                  |   1 +
 .../test_dependencies_locks/.gitignore        |   3 +
 .../modules/test_dependencies_locks/Makefile  |  14 +++
 .../expected/test_dependencies_locks.out      | 113 ++++++++++++++++++
 .../test_dependencies_locks/meson.build       |  12 ++
 .../specs/test_dependencies_locks.spec        |  78 ++++++++++++
 12 files changed, 354 insertions(+)
  24.6% src/backend/catalog/
  42.7% src/test/modules/test_dependencies_locks/expected/
  25.9% src/test/modules/test_dependencies_locks/specs/
   5.0% src/test/modules/test_dependencies_locks/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..a49357bbe2 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,60 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it (for example creating
+		 * a composite type while creating a relation), so bypass the syscache
+		 * lookup and use a dirty snaphot instead to cover this scenario.
+		 */
+		if (!ObjectByIdExist(object, true))
+		{
+			/*
+			 * If the object has been dropped before we get a chance to get
+			 * its description, then emit a generic error message. That looks
+			 * like a good compromise over extra complexity.
+			 */
+			if (object_description)
+				ereport(ERROR, errmsg("%s does not exist", object_description));
+			else
+				ereport(ERROR, errmsg("a dependent object does not exist"));
+		}
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..c2b873dd81 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,76 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot)
+{
+	HeapTuple	tuple;
+	int			cache = -1;
+	const ObjectPropertyType *property;
+
+	if (!use_dirty_snapshot)
+	{
+		property = get_object_property_data(address->classId);
+
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		SnapshotData DirtySnapshot;
+		Snapshot	snapshot;
+
+		if (use_dirty_snapshot)
+		{
+			InitDirtySnapshot(DirtySnapshot);
+			snapshot = &DirtySnapshot;
+		}
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  snapshot, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index f85a898de8..6bb218f5dd 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -106,6 +106,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency. XXX - Should we do so only for DEPENDENCY_NORMAL?
+		 */
+		depLockAndCheckObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index ec654010d4..8915548711 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -94,6 +94,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..04891abcc1 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/modules/Makefile b/src/test/modules/Makefile
index 256799f520..75f357100f 100644
--- a/src/test/modules/Makefile
+++ b/src/test/modules/Makefile
@@ -17,6 +17,7 @@ SUBDIRS = \
 		  test_copy_callbacks \
 		  test_custom_rmgrs \
 		  test_ddl_deparse \
+		  test_dependencies_locks \
 		  test_dsa \
 		  test_dsm_registry \
 		  test_extensions \
diff --git a/src/test/modules/meson.build b/src/test/modules/meson.build
index d8fe059d23..60305dcccd 100644
--- a/src/test/modules/meson.build
+++ b/src/test/modules/meson.build
@@ -16,6 +16,7 @@ subdir('test_bloomfilter')
 subdir('test_copy_callbacks')
 subdir('test_custom_rmgrs')
 subdir('test_ddl_deparse')
+subdir('test_dependencies_locks')
 subdir('test_dsa')
 subdir('test_dsm_registry')
 subdir('test_extensions')
diff --git a/src/test/modules/test_dependencies_locks/.gitignore b/src/test/modules/test_dependencies_locks/.gitignore
new file mode 100644
index 0000000000..bf000faac4
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/.gitignore
@@ -0,0 +1,3 @@
+# Generated subdirectories
+/log/
+/output_iso
diff --git a/src/test/modules/test_dependencies_locks/Makefile b/src/test/modules/test_dependencies_locks/Makefile
new file mode 100644
index 0000000000..7491048380
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/Makefile
@@ -0,0 +1,14 @@
+# src/test/modules/test_dependencies_locks/Makefile
+
+ISOLATION = test_dependencies_locks
+
+ifdef USE_PGXS
+PG_CONFIG = pg_config
+PGXS := $(shell $(PG_CONFIG) --pgxs)
+include $(PGXS)
+else
+subdir = src/test/modules/test_dependencies_locks
+top_builddir = ../../../..
+include $(top_builddir)/src/Makefile.global
+include $(top_srcdir)/contrib/contrib-global.mk
+endif
diff --git a/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..93318c9cbb
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
@@ -0,0 +1,113 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/modules/test_dependencies_locks/meson.build b/src/test/modules/test_dependencies_locks/meson.build
new file mode 100644
index 0000000000..92a978ab93
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/meson.build
@@ -0,0 +1,12 @@
+# Copyright (c) 2024, PostgreSQL Global Development Group
+
+tests += {
+  'name': 'test_dependencies_locks',
+  'sd': meson.current_source_dir(),
+  'bd': meson.current_build_dir(),
+  'isolation': {
+    'specs': [
+      'test_dependencies_locks',
+    ],
+  },
+}
diff --git a/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..3d90a29c47
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
@@ -0,0 +1,78 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-04-25 06:00                 ` Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Alexander Lakhin @ 2024-04-25 06:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

25.04.2024 08:00, Bertrand Drouvot wrote:
>
>> though concurrent create/drop operations can still produce
>> the "cache lookup failed" error, which is probably okay, except that it is
>> an INTERNAL_ERROR, which assumed to be not easily triggered by users.
> I did not see any of those "cache lookup failed" during my testing with/without
> your script. During which test(s) did you see those with v3 applied?

You can try, for example, table-trigger, or other tests that check for
"cache lookup failed" psql output only (maybe you'll need to increase the
iteration count). For instance, I've got (with v4 applied):
2024-04-25 05:48:08.102 UTC [3638763] ERROR:  cache lookup failed for function 20893
2024-04-25 05:48:08.102 UTC [3638763] STATEMENT:  CREATE TRIGGER modified_c1 BEFORE UPDATE OF c ON t
         FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');

Or with function-function:
2024-04-25 05:52:31.390 UTC [3711897] ERROR:  cache lookup failed for function 32190 at character 54
2024-04-25 05:52:31.390 UTC [3711897] STATEMENT:  CREATE FUNCTION f1() RETURNS int LANGUAGE SQL RETURN f() + 1;
--
2024-04-25 05:52:37.639 UTC [3720011] ERROR:  cache lookup failed for function 34465 at character 54
2024-04-25 05:52:37.639 UTC [3720011] STATEMENT:  CREATE FUNCTION f1() RETURNS int LANGUAGE SQL RETURN f() + 1;

> Attached v4, simply adding more tests to v3.

Thank you for working on this!

Best regards,
Alexander

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
@ 2024-04-25 07:20                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-04-25 07:20 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

On Thu, Apr 25, 2024 at 09:00:00AM +0300, Alexander Lakhin wrote:
> Hi,
> 
> 25.04.2024 08:00, Bertrand Drouvot wrote:
> > 
> > > though concurrent create/drop operations can still produce
> > > the "cache lookup failed" error, which is probably okay, except that it is
> > > an INTERNAL_ERROR, which assumed to be not easily triggered by users.
> > I did not see any of those "cache lookup failed" during my testing with/without
> > your script. During which test(s) did you see those with v3 applied?
> 
> You can try, for example, table-trigger, or other tests that check for
> "cache lookup failed" psql output only (maybe you'll need to increase the
> iteration count). For instance, I've got (with v4 applied):
> 2024-04-25 05:48:08.102 UTC [3638763] ERROR:  cache lookup failed for function 20893
> 2024-04-25 05:48:08.102 UTC [3638763] STATEMENT:  CREATE TRIGGER modified_c1 BEFORE UPDATE OF c ON t
>         FOR EACH ROW WHEN (OLD.c <> NEW.c) EXECUTE PROCEDURE trigger_func('modified_c');
> 
> Or with function-function:
> 2024-04-25 05:52:31.390 UTC [3711897] ERROR:  cache lookup failed for function 32190 at character 54
> 2024-04-25 05:52:31.390 UTC [3711897] STATEMENT:  CREATE FUNCTION f1() RETURNS int LANGUAGE SQL RETURN f() + 1;
> --
> 2024-04-25 05:52:37.639 UTC [3720011] ERROR:  cache lookup failed for function 34465 at character 54
> 2024-04-25 05:52:37.639 UTC [3720011] STATEMENT:  CREATE FUNCTION f1() RETURNS int LANGUAGE SQL RETURN f() + 1;

I see, so this is during object creation.

It's easy to reproduce this kind of issue with gdb. For example set a breakpoint
on SearchSysCache1() and during the create function f1() once it breaks on:

#0  SearchSysCache1 (cacheId=45, key1=16400) at syscache.c:221
#1  0x00005ad305beacd6 in func_get_detail (funcname=0x5ad308204d50, fargs=0x0, fargnames=0x0, nargs=0, argtypes=0x7ffff2ff9cc0, expand_variadic=true, expand_defaults=true, include_out_arguments=false, funcid=0x7ffff2ff9ba0, rettype=0x7ffff2ff9b9c, retset=0x7ffff2ff9b94, nvargs=0x7ffff2ff9ba4,
    vatype=0x7ffff2ff9ba8, true_typeids=0x7ffff2ff9bd8, argdefaults=0x7ffff2ff9be0) at parse_func.c:1622
#2  0x00005ad305be7dd0 in ParseFuncOrColumn (pstate=0x5ad30823be98, funcname=0x5ad308204d50, fargs=0x0, last_srf=0x0, fn=0x5ad308204da0, proc_call=false, location=55) at parse_func.c:266
#3  0x00005ad305bdffb0 in transformFuncCall (pstate=0x5ad30823be98, fn=0x5ad308204da0) at parse_expr.c:1474
#4  0x00005ad305bdd2ee in transformExprRecurse (pstate=0x5ad30823be98, expr=0x5ad308204da0) at parse_expr.c:230
#5  0x00005ad305bdec34 in transformAExprOp (pstate=0x5ad30823be98, a=0x5ad308204e20) at parse_expr.c:990
#6  0x00005ad305bdd1a0 in transformExprRecurse (pstate=0x5ad30823be98, expr=0x5ad308204e20) at parse_expr.c:187
#7  0x00005ad305bdd00b in transformExpr (pstate=0x5ad30823be98, expr=0x5ad308204e20, exprKind=EXPR_KIND_SELECT_TARGET) at parse_expr.c:131
#8  0x00005ad305b96b7e in transformReturnStmt (pstate=0x5ad30823be98, stmt=0x5ad308204ee0) at analyze.c:2395
#9  0x00005ad305b92213 in transformStmt (pstate=0x5ad30823be98, parseTree=0x5ad308204ee0) at analyze.c:375
#10 0x00005ad305c6321a in interpret_AS_clause (languageOid=14, languageName=0x5ad308204c40 "sql", funcname=0x5ad308204ad8 "f100", as=0x0, sql_body_in=0x5ad308204ee0, parameterTypes=0x0, inParameterNames=0x0, prosrc_str_p=0x7ffff2ffa208, probin_str_p=0x7ffff2ffa200, sql_body_out=0x7ffff2ffa210,
    queryString=0x5ad3082040b0 "CREATE FUNCTION f100() RETURNS int LANGUAGE SQL RETURN f() + 1;") at functioncmds.c:953
#11 0x00005ad305c63c93 in CreateFunction (pstate=0x5ad308186310, stmt=0x5ad308204f00) at functioncmds.c:1221

then drop function f() in another session. Then the create function f1() would:

postgres=# CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN f() + 1;
ERROR:  cache lookup failed for function 16400

This stuff does appear before we get a chance to call the new depLockAndCheckObject()
function.

I think this is what Tom was referring to in [1]:

"
So the only real fix for this would be to make every object lookup in the entire
system do the sort of dance that's done in RangeVarGetRelidExtended.
"

The fact that those kind of errors appear also somehow ensure that no orphaned
dependencies can be created.

The patch does ensure that no orphaned depencies can occur after those "initial"
look up are done (should the dependent object be dropped).

I'm tempted to not add extra complexity to avoid those kind of errors and keep the
patch as it is. All of those servicing the same goal: no orphaned depencies are
created.

[1]: https://www.postgresql.org/message-id/2872252.1630851337%40sss.pgh.pa.us

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-04-30 17:00                     ` Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Alexander Lakhin @ 2024-04-30 17:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi Bertrand,

25.04.2024 10:20, Bertrand Drouvot wrote:
> postgres=# CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN f() + 1;
> ERROR:  cache lookup failed for function 16400
>
> This stuff does appear before we get a chance to call the new depLockAndCheckObject()
> function.
>
> I think this is what Tom was referring to in [1]:
>
> "
> So the only real fix for this would be to make every object lookup in the entire
> system do the sort of dance that's done in RangeVarGetRelidExtended.
> "
>
> The fact that those kind of errors appear also somehow ensure that no orphaned
> dependencies can be created.

I agree; the only thing that I'd change here, is the error code.

But I've discovered yet another possibility to get a broken dependency.
Please try this script:
res=0
numclients=20
for ((i=1;i<=100;i++)); do
for ((c=1;c<=numclients;c++)); do
   echo "
CREATE SCHEMA s_$c;
CREATE CONVERSION myconv_$c FOR 'LATIN1' TO 'UTF8' FROM iso8859_1_to_utf8;
ALTER CONVERSION myconv_$c SET SCHEMA s_$c;
   " | psql >psql1-$c.log 2>&1 &
   echo "DROP SCHEMA s_$c RESTRICT;" | psql >psql2-$c.log 2>&1 &
done
wait
pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
for ((c=1;c<=numclients;c++)); do
   echo "DROP SCHEMA s_$c CASCADE;" | psql >psql3-$c.log 2>&1
done
done
psql -c "SELECT * FROM pg_conversion WHERE connamespace NOT IN (SELECT oid FROM pg_namespace);"

It fails for me (with the v4 patch applied) as follows:
pg_dump: error: schema with OID 16392 does not exist
on iteration 1
   oid  | conname  | connamespace | conowner | conforencoding | contoencoding |      conproc      | condefault
-------+----------+--------------+----------+----------------+---------------+-------------------+------------
  16396 | myconv_6 |        16392 |       10 |              8 |             6 | iso8859_1_to_utf8 | f

Best regards,
Alexander





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
@ 2024-05-09 12:20                       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-14 12:00                         ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  0 siblings, 2 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2024-05-09 12:20 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

On Tue, Apr 30, 2024 at 08:00:00PM +0300, Alexander Lakhin wrote:
> Hi Bertrand,
> 
> But I've discovered yet another possibility to get a broken dependency.

Thanks for the testing and the report!

> Please try this script:
> res=0
> numclients=20
> for ((i=1;i<=100;i++)); do
> for ((c=1;c<=numclients;c++)); do
>   echo "
> CREATE SCHEMA s_$c;
> CREATE CONVERSION myconv_$c FOR 'LATIN1' TO 'UTF8' FROM iso8859_1_to_utf8;
> ALTER CONVERSION myconv_$c SET SCHEMA s_$c;
>   " | psql >psql1-$c.log 2>&1 &
>   echo "DROP SCHEMA s_$c RESTRICT;" | psql >psql2-$c.log 2>&1 &
> done
> wait
> pg_dump -f db.dump || { echo "on iteration $i"; res=1; break; }
> for ((c=1;c<=numclients;c++)); do
>   echo "DROP SCHEMA s_$c CASCADE;" | psql >psql3-$c.log 2>&1
> done
> done
> psql -c "SELECT * FROM pg_conversion WHERE connamespace NOT IN (SELECT oid FROM pg_namespace);"
> 
> It fails for me (with the v4 patch applied) as follows:
> pg_dump: error: schema with OID 16392 does not exist
> on iteration 1
>   oid  | conname  | connamespace | conowner | conforencoding | contoencoding |      conproc      | condefault
> -------+----------+--------------+----------+----------------+---------------+-------------------+------------
>  16396 | myconv_6 |        16392 |       10 |              8 |             6 | iso8859_1_to_utf8 | f
> 

Thanks for sharing the test, I'm able to reproduce the issue with v4.

Oh I see, your test updates an existing dependency. v4 took care about brand new 
dependencies creation (recordMultipleDependencies()) but forgot to take care
about changing an existing dependency (which is done in another code path:
changeDependencyFor()).

Please find attached v5 that adds:

- a call to the new depLockAndCheckObject() function in changeDependencyFor().
- a test when altering an existing dependency.

With v5 applied, I don't see the issue anymore.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v5-0001-Avoid-orphaned-objects-dependencies.patch (21.5K, ../../Zjy%2Fo3t%2F26exwj5Z@ip-10-97-1-34.eu-west-3.compute.internal/2-v5-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 6fc24a798210f730ab04833fa58074f142be968e Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v5] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/dependency.c              |  54 ++++++++
 src/backend/catalog/objectaddress.c           |  70 ++++++++++
 src/backend/catalog/pg_depend.c               |  12 ++
 src/include/catalog/dependency.h              |   1 +
 src/include/catalog/objectaddress.h           |   1 +
 src/test/modules/Makefile                     |   1 +
 src/test/modules/meson.build                  |   1 +
 .../test_dependencies_locks/.gitignore        |   3 +
 .../modules/test_dependencies_locks/Makefile  |  14 ++
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 .../test_dependencies_locks/meson.build       |  12 ++
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 12 files changed, 387 insertions(+)
  22.9% src/backend/catalog/
  43.7% src/test/modules/test_dependencies_locks/expected/
  27.2% src/test/modules/test_dependencies_locks/specs/
   4.5% src/test/modules/test_dependencies_locks/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..a49357bbe2 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,60 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it (for example creating
+		 * a composite type while creating a relation), so bypass the syscache
+		 * lookup and use a dirty snaphot instead to cover this scenario.
+		 */
+		if (!ObjectByIdExist(object, true))
+		{
+			/*
+			 * If the object has been dropped before we get a chance to get
+			 * its description, then emit a generic error message. That looks
+			 * like a good compromise over extra complexity.
+			 */
+			if (object_description)
+				ereport(ERROR, errmsg("%s does not exist", object_description));
+			else
+				ereport(ERROR, errmsg("a dependent object does not exist"));
+		}
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..c2b873dd81 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,76 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot)
+{
+	HeapTuple	tuple;
+	int			cache = -1;
+	const ObjectPropertyType *property;
+
+	if (!use_dirty_snapshot)
+	{
+		property = get_object_property_data(address->classId);
+
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		SnapshotData DirtySnapshot;
+		Snapshot	snapshot;
+
+		if (use_dirty_snapshot)
+		{
+			InitDirtySnapshot(DirtySnapshot);
+			snapshot = &DirtySnapshot;
+		}
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  snapshot, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 5366f7820c..f16af28429 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -108,6 +108,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency. XXX - Should we do so only for DEPENDENCY_NORMAL?
+		 */
+		depLockAndCheckObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
@@ -506,6 +512,12 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+	/*
+	 * Acquire a lock and check object still exists while changing the
+	 * dependency.
+	 */
+	depLockAndCheckObject(&objAddr);
+
 	depRel = table_open(DependRelationId, RowExclusiveLock);
 
 	/* There should be existing dependency record(s), so search. */
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 7eee66f810..5619b6f55e 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..04891abcc1 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/modules/Makefile b/src/test/modules/Makefile
index 256799f520..75f357100f 100644
--- a/src/test/modules/Makefile
+++ b/src/test/modules/Makefile
@@ -17,6 +17,7 @@ SUBDIRS = \
 		  test_copy_callbacks \
 		  test_custom_rmgrs \
 		  test_ddl_deparse \
+		  test_dependencies_locks \
 		  test_dsa \
 		  test_dsm_registry \
 		  test_extensions \
diff --git a/src/test/modules/meson.build b/src/test/modules/meson.build
index d8fe059d23..60305dcccd 100644
--- a/src/test/modules/meson.build
+++ b/src/test/modules/meson.build
@@ -16,6 +16,7 @@ subdir('test_bloomfilter')
 subdir('test_copy_callbacks')
 subdir('test_custom_rmgrs')
 subdir('test_ddl_deparse')
+subdir('test_dependencies_locks')
 subdir('test_dsa')
 subdir('test_dsm_registry')
 subdir('test_extensions')
diff --git a/src/test/modules/test_dependencies_locks/.gitignore b/src/test/modules/test_dependencies_locks/.gitignore
new file mode 100644
index 0000000000..bf000faac4
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/.gitignore
@@ -0,0 +1,3 @@
+# Generated subdirectories
+/log/
+/output_iso
diff --git a/src/test/modules/test_dependencies_locks/Makefile b/src/test/modules/test_dependencies_locks/Makefile
new file mode 100644
index 0000000000..7491048380
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/Makefile
@@ -0,0 +1,14 @@
+# src/test/modules/test_dependencies_locks/Makefile
+
+ISOLATION = test_dependencies_locks
+
+ifdef USE_PGXS
+PG_CONFIG = pg_config
+PGXS := $(shell $(PG_CONFIG) --pgxs)
+include $(PGXS)
+else
+subdir = src/test/modules/test_dependencies_locks
+top_builddir = ../../../..
+include $(top_builddir)/src/Makefile.global
+include $(top_srcdir)/contrib/contrib-global.mk
+endif
diff --git a/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/modules/test_dependencies_locks/meson.build b/src/test/modules/test_dependencies_locks/meson.build
new file mode 100644
index 0000000000..92a978ab93
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/meson.build
@@ -0,0 +1,12 @@
+# Copyright (c) 2024, PostgreSQL Global Development Group
+
+tests += {
+  'name': 'test_dependencies_locks',
+  'sd': meson.current_source_dir(),
+  'bd': meson.current_build_dir(),
+  'isolation': {
+    'specs': [
+      'test_dependencies_locks',
+    ],
+  },
+}
diff --git a/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-05-14 12:00                         ` Alexander Lakhin <exclusion@gmail.com>
  2024-05-15 08:33                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Alexander Lakhin @ 2024-05-14 12:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi Bertrand,

09.05.2024 15:20, Bertrand Drouvot wrote:
> Oh I see, your test updates an existing dependency. v4 took care about brand new
> dependencies creation (recordMultipleDependencies()) but forgot to take care
> about changing an existing dependency (which is done in another code path:
> changeDependencyFor()).
>
> Please find attached v5 that adds:
>
> - a call to the new depLockAndCheckObject() function in changeDependencyFor().
> - a test when altering an existing dependency.
>
> With v5 applied, I don't see the issue anymore.

Me too. Thank you for the improved version!
I will test the patch in the background, but for now I see no other
issues with it.

Best regards,
Alexander





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-14 12:00                         ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
@ 2024-05-15 08:33                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2024-05-15 08:33 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi,

On Tue, May 14, 2024 at 03:00:00PM +0300, Alexander Lakhin wrote:
> Hi Bertrand,
> 
> 09.05.2024 15:20, Bertrand Drouvot wrote:
> > Oh I see, your test updates an existing dependency. v4 took care about brand new
> > dependencies creation (recordMultipleDependencies()) but forgot to take care
> > about changing an existing dependency (which is done in another code path:
> > changeDependencyFor()).
> > 
> > Please find attached v5 that adds:
> > 
> > - a call to the new depLockAndCheckObject() function in changeDependencyFor().
> > - a test when altering an existing dependency.
> > 
> > With v5 applied, I don't see the issue anymore.
> 
> Me too. Thank you for the improved version!
> I will test the patch in the background, but for now I see no other
> issues with it.

Thanks for confirming!

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-05-15 01:14                         ` Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Michael Paquier @ 2024-05-15 01:14 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org

On Thu, May 09, 2024 at 12:20:51PM +0000, Bertrand Drouvot wrote:
> Oh I see, your test updates an existing dependency. v4 took care about brand new 
> dependencies creation (recordMultipleDependencies()) but forgot to take care
> about changing an existing dependency (which is done in another code path:
> changeDependencyFor()).
> 
> Please find attached v5 that adds:
> 
> - a call to the new depLockAndCheckObject() function in changeDependencyFor().
> - a test when altering an existing dependency.
> 
> With v5 applied, I don't see the issue anymore.

+            if (object_description)
+                ereport(ERROR, errmsg("%s does not exist", object_description));
+            else
+                ereport(ERROR, errmsg("a dependent object does not ex

This generates an internal error code.  Is that intended?

--- /dev/null
+++ b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec 

This introduces a module with only one single spec.  I could get
behind an extra module if splitting the tests into more specs makes
sense or if there is a restriction on installcheck.  However, for 
one spec file filed with a bunch of objects, and note that I'm OK to
let this single spec grow more for this range of tests, it seems to me
that this would be better under src/test/isolation/.

+		if (use_dirty_snapshot)
+		{
+			InitDirtySnapshot(DirtySnapshot);
+			snapshot = &DirtySnapshot;
+		}
+		else
+			snapshot = NULL;

I'm wondering if Robert has a comment about that.  It looks backwards
in a world where we try to encourage MVCC snapshots for catalog
scans (aka 568d4138c646), especially for the part related to
dependency.c and ObjectAddresses.
--
Michael

Attachments:

  [application/pgp-signature] signature.asc (832B, ../../ZkQMYVxbOxFD0519@paquier.xyz/2-signature.asc)
  download

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
@ 2024-05-15 08:31                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-19 08:00                             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2024-05-15 08:31 UTC (permalink / raw)
  To: Michael Paquier <michael@paquier.xyz>; +Cc: Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org

Hi,

On Wed, May 15, 2024 at 10:14:09AM +0900, Michael Paquier wrote:
> On Thu, May 09, 2024 at 12:20:51PM +0000, Bertrand Drouvot wrote:
> > Oh I see, your test updates an existing dependency. v4 took care about brand new 
> > dependencies creation (recordMultipleDependencies()) but forgot to take care
> > about changing an existing dependency (which is done in another code path:
> > changeDependencyFor()).
> > 
> > Please find attached v5 that adds:
> > 
> > - a call to the new depLockAndCheckObject() function in changeDependencyFor().
> > - a test when altering an existing dependency.
> > 
> > With v5 applied, I don't see the issue anymore.
> 
> +            if (object_description)
> +                ereport(ERROR, errmsg("%s does not exist", object_description));
> +            else
> +                ereport(ERROR, errmsg("a dependent object does not ex
> 
> This generates an internal error code.  Is that intended?

Thanks for looking at it!

Yes, it's like when say you want to create an object in a schema that does not
exist (see get_namespace_oid()).

> --- /dev/null
> +++ b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec 
> 
> This introduces a module with only one single spec.  I could get
> behind an extra module if splitting the tests into more specs makes
> sense or if there is a restriction on installcheck.  However, for 
> one spec file filed with a bunch of objects, and note that I'm OK to
> let this single spec grow more for this range of tests, it seems to me
> that this would be better under src/test/isolation/.

Yeah, I was not sure about this one (the location is from take 2 mentioned
up-thread). I'll look at moving the tests to src/test/isolation/.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-05-15 10:31                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-05-15 10:31 UTC (permalink / raw)
  To: Michael Paquier <michael@paquier.xyz>; +Cc: Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org

Hi,

On Wed, May 15, 2024 at 08:31:43AM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Wed, May 15, 2024 at 10:14:09AM +0900, Michael Paquier wrote:
> > +++ b/src/test/modules/test_dependencies_locks/specs/test_dependencies_locks.spec 
> > 
> > This introduces a module with only one single spec.  I could get
> > behind an extra module if splitting the tests into more specs makes
> > sense or if there is a restriction on installcheck.  However, for 
> > one spec file filed with a bunch of objects, and note that I'm OK to
> > let this single spec grow more for this range of tests, it seems to me
> > that this would be better under src/test/isolation/.
> 
> Yeah, I was not sure about this one (the location is from take 2 mentioned
> up-thread). I'll look at moving the tests to src/test/isolation/.

Please find attached v6 (only diff with v5 is moving the tests as suggested
above).

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v6-0001-Avoid-orphaned-objects-dependencies.patch (19.2K, ../../ZkSO5qlRNnFimJev@ip-10-97-1-34.eu-west-3.compute.internal/2-v6-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 59f7befd34b8aa4ba0483a100e85bacbc1a76707 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v6] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/dependency.c              |  54 ++++++++
 src/backend/catalog/objectaddress.c           |  70 ++++++++++
 src/backend/catalog/pg_depend.c               |  12 ++
 src/include/catalog/dependency.h              |   1 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 8 files changed, 357 insertions(+)
  24.1% src/backend/catalog/
  45.9% src/test/isolation/expected/
  28.6% src/test/isolation/specs/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..a49357bbe2 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,60 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it (for example creating
+		 * a composite type while creating a relation), so bypass the syscache
+		 * lookup and use a dirty snaphot instead to cover this scenario.
+		 */
+		if (!ObjectByIdExist(object, true))
+		{
+			/*
+			 * If the object has been dropped before we get a chance to get
+			 * its description, then emit a generic error message. That looks
+			 * like a good compromise over extra complexity.
+			 */
+			if (object_description)
+				ereport(ERROR, errmsg("%s does not exist", object_description));
+			else
+				ereport(ERROR, errmsg("a dependent object does not exist"));
+		}
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..c2b873dd81 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,76 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot)
+{
+	HeapTuple	tuple;
+	int			cache = -1;
+	const ObjectPropertyType *property;
+
+	if (!use_dirty_snapshot)
+	{
+		property = get_object_property_data(address->classId);
+
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		SnapshotData DirtySnapshot;
+		Snapshot	snapshot;
+
+		if (use_dirty_snapshot)
+		{
+			InitDirtySnapshot(DirtySnapshot);
+			snapshot = &DirtySnapshot;
+		}
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  snapshot, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 5366f7820c..f16af28429 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -108,6 +108,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency. XXX - Should we do so only for DEPENDENCY_NORMAL?
+		 */
+		depLockAndCheckObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
@@ -506,6 +512,12 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+	/*
+	 * Acquire a lock and check object still exists while changing the
+	 * dependency.
+	 */
+	depLockAndCheckObject(&objAddr);
+
 	depRel = table_open(DependRelationId, RowExclusiveLock);
 
 	/* There should be existing dependency record(s), so search. */
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 7eee66f810..5619b6f55e 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..04891abcc1 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 0342eb39e4..1b67f0bffe 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -114,3 +114,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-05-21 12:53                               ` Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Robert Haas @ 2024-05-21 12:53 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org

On Wed, May 15, 2024 at 6:31 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> Please find attached v6 (only diff with v5 is moving the tests as suggested
> above).

I don't immediately know what to think about this patch. I've known
about this issue for a long time, but I didn't think this was how we
would fix it.

I think the problem here is basically that we don't lock namespaces
(schemas) when we're adding and removing things from the schema. So I
assumed that if we ever did something about this, what we would do
would be add a bunch of calls to lock schemas to the appropriate parts
of the code. What you've done here instead is add locking at a much
lower level - whenever we are adding a dependency on an object, we
lock the object. The advantage of that approach is that we definitely
won't miss anything. The disadvantage of that approach is that it
means we have some very low-level code taking locks, which means it's
not obvious which operations are taking what locks. Maybe it could
even result in some redundancy, like the higher-level code taking a
lock also (possibly in a different mode) and then this code taking
another one.

I haven't gone through the previous threads; it sounds like there's
already been some discussion of this, but I'm just telling you how it
strikes me on first look.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-05-22 10:21                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-05-22 10:21 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org

Hi,

On Tue, May 21, 2024 at 08:53:06AM -0400, Robert Haas wrote:
> On Wed, May 15, 2024 at 6:31 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > Please find attached v6 (only diff with v5 is moving the tests as suggested
> > above).
> 
> I don't immediately know what to think about this patch.

Thanks for looking at it!

> I've known about this issue for a long time, but I didn't think this was how we
> would fix it.

I started initially with [1] but it was focusing on function-schema only.

Then I proposed [2] making use of a dirty snapshot when recording the dependency.
But this approach appeared to be "scary" and it was still failing to close
some race conditions.

Then, Tom proposed another approach in [2] which is that "creation DDL will have
to take a lock on each referenced object that'd conflict with a lock taken by DROP".
This is the one the current patch is trying to implement.

> What you've done here instead is add locking at a much
> lower level - whenever we are adding a dependency on an object, we
> lock the object. The advantage of that approach is that we definitely
> won't miss anything.

Right, as there is much more than the ones related to schemas, for example:

- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper

to name a few.

> The disadvantage of that approach is that it
> means we have some very low-level code taking locks, which means it's
> not obvious which operations are taking what locks.

Right, but the new operations are "only" the ones leading to recording or altering
a dependency.

> Maybe it could
> even result in some redundancy, like the higher-level code taking a
> lock also (possibly in a different mode) and then this code taking
> another one.

The one that is added here is in AccessShareLock mode. It could conflict with
the ones in AccessExclusiveLock means (If I'm not missing any):

- AcquireDeletionLock(): which is exactly what we want
- get_object_address()
    - get_object_address_rv()
        - ExecAlterObjectDependsStmt()
    - ExecRenameStmt()
    - ExecAlterObjectDependsStmt()
    - ExecAlterOwnerStmt()
    - RemoveObjects()
- AlterPublication()

I think there is 2 cases here:

First case: the "conflicting" lock mode is for one of our own lock then LockCheckConflicts()
would report this as a NON conflict.

Second case: the "conflicting" lock mode is NOT for one of our own lock then LockCheckConflicts()
would report a conflict. But I've the feeling that the existing code would
already lock those sessions.

One example where it would be the case:

Session 1: doing "BEGIN; ALTER FUNCTION noschemas.foo2() SET SCHEMA alterschema" would
acquire the lock in AccessExclusiveLock during ExecAlterObjectSchemaStmt()->get_object_address()->LockDatabaseObject()
(in the existing code and before the new call that would occur through changeDependencyFor()->depLockAndCheckObject()
with the patch in place).

Then, session 2: doing "alter function noschemas.foo2() owner to newrole;"
would be locked in the existing code while doing ExecAlterOwnerStmt()->get_object_address()->LockDatabaseObject()).

Means that in this example, the new lock this patch is introducing would not be
responsible of session 2 beging locked.

Was your concern about "First case" or "Second case" or both?

[1]: https://www.postgresql.org/message-id/flat/5a9daaae-5538-b209-6279-e903c3ea2157%40amazon.com
[2]: https://www.postgresql.org/message-id/flat/8369ff70-0e31-f194-2954-787f4d9e21dd%40amazon.com

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-05-22 14:48                                   ` Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Robert Haas @ 2024-05-22 14:48 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Wed, May 22, 2024 at 6:21 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> I started initially with [1] but it was focusing on function-schema only.

Yeah, that's what I thought we would want to do. And then just extend
that to the other cases.

> Then I proposed [2] making use of a dirty snapshot when recording the dependency.
> But this approach appeared to be "scary" and it was still failing to close
> some race conditions.

The current patch still seems to be using dirty snapshots for some
reason, which struck me as a bit odd. My intuition is that if we're
relying on dirty snapshots to solve problems, we likely haven't solved
the problems correctly, which seems consistent with your statement
about "failing to close some race conditions". But I don't think I
understand the situation well enough to be sure just yet.

> Then, Tom proposed another approach in [2] which is that "creation DDL will have
> to take a lock on each referenced object that'd conflict with a lock taken by DROP".
> This is the one the current patch is trying to implement.

It's a clever idea, but I'm not sure that I like it.

> I think there is 2 cases here:
>
> First case: the "conflicting" lock mode is for one of our own lock then LockCheckConflicts()
> would report this as a NON conflict.
>
> Second case: the "conflicting" lock mode is NOT for one of our own lock then LockCheckConflicts()
> would report a conflict. But I've the feeling that the existing code would
> already lock those sessions.
>
> Was your concern about "First case" or "Second case" or both?

The second case, I guess. It's bad to take a weaker lock first and
then a stronger lock on the same object later, because it can lead to
deadlocks that would have been avoided if the stronger lock had been
taken at the outset. Here, it seems like things would happen in the
other order: if we took two locks, we'd probably take the stronger
lock in the higher-level code and then the weaker lock in the
dependency code. That shouldn't break anything; it's just a bit
inefficient. My concern was really more about the maintainability of
the code. I fear that if we add code that takes heavyweight locks in
surprising places, we might later find the behavior difficult to
reason about.

Tom, what is your thought about that concern?

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-05-23 04:19                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-05-23 04:19 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, May 22, 2024 at 10:48:12AM -0400, Robert Haas wrote:
> On Wed, May 22, 2024 at 6:21 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > I started initially with [1] but it was focusing on function-schema only.
> 
> Yeah, that's what I thought we would want to do. And then just extend
> that to the other cases.
> 
> > Then I proposed [2] making use of a dirty snapshot when recording the dependency.
> > But this approach appeared to be "scary" and it was still failing to close
> > some race conditions.
> 
> The current patch still seems to be using dirty snapshots for some
> reason, which struck me as a bit odd. My intuition is that if we're
> relying on dirty snapshots to solve problems, we likely haven't solved
> the problems correctly, which seems consistent with your statement
> about "failing to close some race conditions". But I don't think I
> understand the situation well enough to be sure just yet.

The reason why we are using a dirty snapshot here is for the cases where we are
recording a dependency on a referenced object that we are creating at the same
time behind the scene (for example, creating a composite type while creating
a relation). Without the dirty snapshot, then the object we are creating behind
the scene (the composite type) would not be visible and we would wrongly assume
that it has been dropped.

Note that the usage of the dirty snapshot is only when the object is first
reported as "non existing" by the new ObjectByIdExist() function.

> > I think there is 2 cases here:
> >
> > First case: the "conflicting" lock mode is for one of our own lock then LockCheckConflicts()
> > would report this as a NON conflict.
> >
> > Second case: the "conflicting" lock mode is NOT for one of our own lock then LockCheckConflicts()
> > would report a conflict. But I've the feeling that the existing code would
> > already lock those sessions.
> >
> > Was your concern about "First case" or "Second case" or both?
> 
> The second case, I guess. It's bad to take a weaker lock first and
> then a stronger lock on the same object later, because it can lead to
> deadlocks that would have been avoided if the stronger lock had been
> taken at the outset.

In the example I shared up-thread that would be the opposite: the Session 1 would
take an AccessExclusiveLock lock on the object before taking an AccessShareLock
during changeDependencyFor().

> Here, it seems like things would happen in the
> other order: if we took two locks, we'd probably take the stronger
> lock in the higher-level code and then the weaker lock in the
> dependency code.

Yeah, I agree.

> That shouldn't break anything; it's just a bit
> inefficient.

Yeah, the second lock is useless in that case (like in the example up-thread).

> My concern was really more about the maintainability of
> the code. I fear that if we add code that takes heavyweight locks in
> surprising places, we might later find the behavior difficult to
> reason about.
>

I think I understand your concern about code maintainability but I'm not sure
that adding locks while recording a dependency is that surprising.

> Tom, what is your thought about that concern?

+1

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-05-23 18:10                                       ` Robert Haas <robertmhaas@gmail.com>
  2024-05-23 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Robert Haas @ 2024-05-23 18:10 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Thu, May 23, 2024 at 12:19 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> The reason why we are using a dirty snapshot here is for the cases where we are
> recording a dependency on a referenced object that we are creating at the same
> time behind the scene (for example, creating a composite type while creating
> a relation). Without the dirty snapshot, then the object we are creating behind
> the scene (the composite type) would not be visible and we would wrongly assume
> that it has been dropped.

The usual reason for using a dirty snapshot is that you want to see
uncommitted work by other transactions. It sounds like you're saying
you just need to see uncommitted work by the same transaction. If
that's true, I think using HeapTupleSatisfiesSelf would be clearer. Or
maybe we just need to put CommandCounterIncrement() calls in the right
places to avoid having the problem in the first place. Or maybe this
is another sign that we're doing the work at the wrong level.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-05-23 21:12                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2024-05-23 21:12 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, May 23, 2024 at 02:10:54PM -0400, Robert Haas wrote:
> On Thu, May 23, 2024 at 12:19 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > The reason why we are using a dirty snapshot here is for the cases where we are
> > recording a dependency on a referenced object that we are creating at the same
> > time behind the scene (for example, creating a composite type while creating
> > a relation). Without the dirty snapshot, then the object we are creating behind
> > the scene (the composite type) would not be visible and we would wrongly assume
> > that it has been dropped.
> 
> The usual reason for using a dirty snapshot is that you want to see
> uncommitted work by other transactions. It sounds like you're saying
> you just need to see uncommitted work by the same transaction.

Right.

> If that's true, I think using HeapTupleSatisfiesSelf would be clearer.

Oh thanks! I did not know about the SNAPSHOT_SELF snapshot type (I should have
check all the snapshot types first though) and that's exactly what is needed here.

Please find attached v8 making use of SnapshotSelf instead of a dirty snapshot.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v8-0001-Avoid-orphaned-objects-dependencies.patch (20.0K, ../../Zk+xPNrxObcmXzO6@ip-10-97-1-34.eu-west-3.compute.internal/2-v8-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 2611fb874a476c1a8d665f97d973193beb70292a Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v8] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/dependency.c              |  59 ++++++++
 src/backend/catalog/objectaddress.c           |  66 +++++++++
 src/backend/catalog/pg_depend.c               |  12 ++
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   1 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 9 files changed, 359 insertions(+)
  24.3% src/backend/catalog/
  45.3% src/test/isolation/expected/
  28.2% src/test/isolation/specs/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..4271ed7c5b 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,65 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it (for example creating
+		 * a composite type while creating a relation), so bypass the syscache
+		 * lookup and use a SnapshotSelf snapshot instead to cover this
+		 * scenario.
+		 */
+		if (!ObjectByIdExist(object, true))
+		{
+			/*
+			 * If the object has been dropped before we get a chance to get
+			 * its description, then emit a generic error message. That looks
+			 * like a good compromise over extra complexity.
+			 */
+			if (object_description)
+				ereport(ERROR,
+						(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+						 errmsg("%s does not exist", object_description)));
+			else
+				ereport(ERROR,
+						(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+						 errmsg("a dependent object does not exist")));
+		}
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..115cb1572e 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,72 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_snapshot_self)
+{
+	HeapTuple	tuple;
+	int			cache = -1;
+	const ObjectPropertyType *property;
+
+	if (!use_snapshot_self)
+	{
+		property = get_object_property_data(address->classId);
+
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		Snapshot	snapshot;
+
+		if (use_snapshot_self)
+			snapshot = SnapshotSelf;
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  snapshot, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 5366f7820c..f16af28429 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -108,6 +108,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency. XXX - Should we do so only for DEPENDENCY_NORMAL?
+		 */
+		depLockAndCheckObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
@@ -506,6 +512,12 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+	/*
+	 * Acquire a lock and check object still exists while changing the
+	 * dependency.
+	 */
+	depLockAndCheckObject(&objAddr);
+
 	depRel = table_open(DependRelationId, RowExclusiveLock);
 
 	/* There should be existing dependency record(s), so search. */
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1..60e8539fe3 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 7eee66f810..5619b6f55e 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..53ee9ad9e6 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_snapshot_self);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 0342eb39e4..1b67f0bffe 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -114,3 +114,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-06-06 05:56                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-06 05:56 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, May 23, 2024 at 02:10:54PM -0400, Robert Haas wrote:
> On Thu, May 23, 2024 at 12:19 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > The reason why we are using a dirty snapshot here is for the cases where we are
> > recording a dependency on a referenced object that we are creating at the same
> > time behind the scene (for example, creating a composite type while creating
> > a relation). Without the dirty snapshot, then the object we are creating behind
> > the scene (the composite type) would not be visible and we would wrongly assume
> > that it has been dropped.
> 
> The usual reason for using a dirty snapshot is that you want to see
> uncommitted work by other transactions. It sounds like you're saying
> you just need to see uncommitted work by the same transaction. If
> that's true, I think using HeapTupleSatisfiesSelf would be clearer. Or
> maybe we just need to put CommandCounterIncrement() calls in the right
> places to avoid having the problem in the first place. Or maybe this
> is another sign that we're doing the work at the wrong level.

Thanks for having discussed your concern with Tom last week during pgconf.dev
and shared the outcome to me. I understand your concern regarding code
maintainability with the current approach.

Please find attached v9 that:

- Acquire the lock and check for object existence at an upper level, means before
calling recordDependencyOn() and recordMultipleDependencies().

- Get rid of the SNAPSHOT_SELF snapshot usage and relies on
CommandCounterIncrement() instead to ensure new entries are visible when
we check for object existence (for the cases where we create additional object
behind the scene: like composite type while creating a relation).

- Add an assertion in recordMultipleDependencies() to ensure that we locked the
object before recording the dependency (to ensure we don't miss any cases now that
the lock is acquired at an upper level).

A few remarks:

My first attempt has been to move eliminate_duplicate_dependencies() out of
record_object_address_dependencies() so that we get the calls in this order:

eliminate_duplicate_dependencies()
depLockAndCheckObjects()
record_object_address_dependencies()

What I'm doing instead in v9 is to rename record_object_address_dependencies()
to lock_record_object_address_dependencies() and add depLockAndCheckObjects()
in it at the right place. That way the caller of
[lock_]record_object_address_dependencies() is not responsible of calling
eliminate_duplicate_dependencies() (which would have been the case with my first
attempt).

We need to setup the LOCKTAG before calling the new Assert in
recordMultipleDependencies(). So, using "#ifdef USE_ASSERT_CHECKING" here to
not setup the LOCKTAG on a non Assert enabled build.

v9 is more invasive (as it changes code in much more places) than v8 but it is
easier to follow (as it is now clear where the new lock is acquired).

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v9-0001-Avoid-orphaned-objects-dependencies.patch (66.2K, ../../ZmFPfmSms4IyyO8T@ip-10-97-1-34.eu-west-3.compute.internal/2-v9-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 6b6ee40fab0b011e9858a0a25624935c59732bfd Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v9] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              |  83 +++++++++--
 src/backend/catalog/heap.c                    |   7 +-
 src/backend/catalog/index.c                   |  16 ++-
 src/backend/catalog/objectaddress.c           |  57 ++++++++
 src/backend/catalog/pg_aggregate.c            |   2 +-
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   2 +-
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  10 +-
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  34 ++++-
 src/backend/catalog/pg_operator.c             |   2 +-
 src/backend/catalog/pg_proc.c                 |  12 +-
 src/backend/catalog/pg_publication.c          |   5 +
 src/backend/catalog/pg_range.c                |   3 +-
 src/backend/catalog/pg_type.c                 |  18 ++-
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   3 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   2 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   4 +-
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   3 +-
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 +++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   2 +-
 src/backend/commands/sequence.c               |   1 +
 src/backend/commands/statscmds.c              |   3 +
 src/backend/commands/tablecmds.c              |  10 ++
 src/backend/commands/trigger.c                |  18 ++-
 src/backend/commands/tsearchcmds.c            |   8 +-
 src/backend/commands/typecmds.c               |   4 +
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   9 +-
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 42 files changed, 534 insertions(+), 43 deletions(-)
  34.8% src/backend/catalog/
  16.2% src/backend/commands/
  28.0% src/test/isolation/expected/
  17.4% src/test/isolation/specs/
   3.3% src/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 143876b77f..6b91402a9f 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1413,6 +1413,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				depLockAndCheckObject(&referenced);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..42293220fd 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,68 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	if (isObjectPinned(object))
+		return;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+void
+depLockAndCheckObjects(const ObjectAddress *object, int nobject)
+{
+	int			i;
+
+	if (nobject < 0)
+		return;
+
+	for (i = 0; i < nobject; i++, object++)
+		depLockAndCheckObject(object);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1562,13 +1624,8 @@ recordDependencyOnExpr(const ObjectAddress *depender,
 	/* Scan the expression tree for referenceable objects */
 	find_expr_references_walker(expr, &context);
 
-	/* Remove any duplicates */
-	eliminate_duplicate_dependencies(context.addrs);
-
-	/* And record 'em */
-	recordMultipleDependencies(depender,
-							   context.addrs->refs, context.addrs->numrefs,
-							   behavior);
+	/* Record all of them (this includes duplicate elimination) */
+	lock_record_object_address_dependencies(depender, context.addrs, behavior);
 
 	free_object_addresses(context.addrs);
 }
@@ -1652,9 +1709,12 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 
 		/* Record the self-dependencies with the appropriate direction */
 		if (!reverse_self)
+		{
+			depLockAndCheckObjects(self_addrs->refs, self_addrs->numrefs);
 			recordMultipleDependencies(depender,
 									   self_addrs->refs, self_addrs->numrefs,
 									   self_behavior);
+		}
 		else
 		{
 			/* Can't use recordMultipleDependencies, so do it the hard way */
@@ -1664,6 +1724,7 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 			{
 				ObjectAddress *thisobj = self_addrs->refs + selfref;
 
+				depLockAndCheckObject(depender);
 				recordDependencyOn(thisobj, depender, self_behavior);
 			}
 		}
@@ -1672,6 +1733,7 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 	}
 
 	/* Record the external dependencies */
+	depLockAndCheckObjects(context.addrs->refs, context.addrs->numrefs);
 	recordMultipleDependencies(depender,
 							   context.addrs->refs, context.addrs->numrefs,
 							   behavior);
@@ -2737,11 +2799,12 @@ stack_address_present_add_flags(const ObjectAddress *object,
  * removing any duplicates.
  */
 void
-record_object_address_dependencies(const ObjectAddress *depender,
-								   ObjectAddresses *referenced,
-								   DependencyType behavior)
+lock_record_object_address_dependencies(const ObjectAddress *depender,
+										ObjectAddresses *referenced,
+										DependencyType behavior)
 {
 	eliminate_duplicate_dependencies(referenced);
+	depLockAndCheckObjects(referenced->refs, referenced->numrefs);
 	recordMultipleDependencies(depender,
 							   referenced->refs, referenced->numrefs,
 							   behavior);
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index a122bbffce..113b275fe1 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -843,6 +843,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId,
 						 tupdesc->attrs[i].atttypid);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -851,6 +852,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 tupdesc->attrs[i].attcollation);
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1471,7 +1473,7 @@ heap_create_with_catalog(const char *relname,
 			add_exact_object_address(&referenced, addrs);
 		}
 
-		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+		lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 		free_object_addresses(addrs);
 	}
 
@@ -3393,7 +3395,7 @@ StorePartitionKey(Relation rel,
 		}
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	/*
@@ -3409,6 +3411,7 @@ StorePartitionKey(Relation rel,
 
 		ObjectAddressSubSet(referenced, RelationRelationId,
 							RelationGetRelid(rel), partattrs[i]);
+		depLockAndCheckObject(&myself);
 		recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index 55fdde4b24..26201e7610 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1144,7 +1144,7 @@ index_create(Relation heapRelation,
 				add_exact_object_address(&referenced, addrs);
 			}
 
-			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
+			lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
 			free_object_addresses(addrs);
 		}
 
@@ -1157,9 +1157,11 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1185,7 +1187,7 @@ index_create(Relation heapRelation,
 			add_exact_object_address(&referenced, addrs);
 		}
 
-		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+		lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 		free_object_addresses(addrs);
 
 		/* Store dependencies on anything mentioned in index expressions */
@@ -1987,6 +1989,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement here to ensure the new constraint entry is
+	 * visible when we'll check of object existence when recording the
+	 * dependencies.
+	 */
+	CommandCounterIncrement();
+	depLockAndCheckObject(&myself);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -1998,9 +2008,11 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..6d7abd3738 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949..9b5c8c8fb0 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -805,7 +805,7 @@ AggregateCreate(const char *aggName,
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 	return myself;
 }
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d..47b7fe75ad 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	depLockAndCheckObject(&colobject);
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d51..2593bb3634 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -121,7 +121,7 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, behavior);
+	lock_record_object_address_dependencies(&myself, addrs, behavior);
 	free_object_addresses(addrs);
 
 	/* dependency on extension */
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f701229..43ceb426d4 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 3baf9231ed..91af823ee5 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -277,8 +277,8 @@ CreateConstraintEntry(const char *constraintName,
 		add_exact_object_address(&domobject, addrs_auto);
 	}
 
-	record_object_address_dependencies(&conobject, addrs_auto,
-									   DEPENDENCY_AUTO);
+	lock_record_object_address_dependencies(&conobject, addrs_auto,
+											DEPENDENCY_AUTO);
 	free_object_addresses(addrs_auto);
 
 	/* Handle set of normal dependencies */
@@ -352,8 +352,8 @@ CreateConstraintEntry(const char *constraintName,
 		}
 	}
 
-	record_object_address_dependencies(&conobject, addrs_normal,
-									   DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&conobject, addrs_normal,
+											DEPENDENCY_NORMAL);
 	free_object_addresses(addrs_normal);
 
 	/*
@@ -858,9 +858,11 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac..479dd528eb 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index cfd7ef51df..47968ee8c8 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,21 +20,20 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
-
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
  * The first argument is the dependent object, the second the one it
@@ -100,6 +99,25 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		LOCKTAG		tag;
+
+		SET_LOCKTAG_OBJECT(tag,
+						   MyDatabaseId,
+						   referenced->classId,
+						   referenced->objectId,
+						   0);
+
+		/*
+		 * Assert the referenced object is locked (see
+		 * depLockAndCheckObject()) when recording the dependency.
+		 */
+		Assert(isObjectPinned(referenced) ||
+			   referenced->classId == RelationRelationId ||
+			   referenced->classId == AuthMemRelationId ||
+			   LockHeldByMe(&tag, AccessShareLock));
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -239,6 +257,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		depLockAndCheckObject(&extension);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -501,11 +520,18 @@ changeDependencyFor(Oid classId, Oid objectId,
 		depAddr.classId = classId;
 		depAddr.objectId = objectId;
 		depAddr.objectSubId = 0;
+		depLockAndCheckObject(&objAddr);
 		recordDependencyOn(&depAddr, &objAddr, DEPENDENCY_NORMAL);
 
 		return 1;
 	}
 
+	/*
+	 * Acquire a lock and check object still exists while changing the
+	 * dependency.
+	 */
+	depLockAndCheckObject(&objAddr);
+
 	depRel = table_open(DependRelationId, RowExclusiveLock);
 
 	/* There should be existing dependency record(s), so search. */
@@ -706,7 +732,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a..7e40471baf 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -930,7 +930,7 @@ makeOperatorDependencies(HeapTuple tuple,
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	/* Dependency on owner */
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f..aa36a07648 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement here to ensure the new function entry is
+	 * visible when we'll check of object existence when recording the
+	 * dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -637,7 +644,7 @@ ProcedureCreate(const char *procedureName,
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	/* dependency on SQL routine body */
@@ -674,9 +681,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 0602398a54..6654b65f41 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -438,10 +438,12 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -454,6 +456,7 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	for (int i = 0; i < natts; i++)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, attarray[i]);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -661,10 +664,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba410..a2f343a81a 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -92,13 +92,14 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	/* record multirange type's dependency on the range type */
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	depLockAndCheckObject(&myself);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed8..91139e275f 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -494,6 +494,14 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement here to ensure the new type  entry is
+		 * visible when we'll check of object existence when recording the
+		 * dependencies.
+		 */
+		CommandCounterIncrement();
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +513,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
@@ -703,7 +712,7 @@ GenerateTypeDependencies(HeapTuple typeTuple,
 		add_exact_object_address(&referenced, addrs_normal);
 	}
 
-	record_object_address_dependencies(&myself, addrs_normal, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs_normal, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs_normal);
 
 	/* Normal dependency on the default expression. */
@@ -724,9 +733,15 @@ GenerateTypeDependencies(HeapTuple typeTuple,
 		ObjectAddressSet(referenced, RelationRelationId, typeForm->typrelid);
 
 		if (relationKind != RELKIND_COMPOSITE_TYPE)
+		{
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
+		}
 		else
+		{
+			depLockAndCheckObject(&myself);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
+		}
 	}
 
 	/*
@@ -737,6 +752,7 @@ GenerateTypeDependencies(HeapTuple typeTuple,
 	if (OidIsValid(typeForm->typelem))
 	{
 		ObjectAddressSet(referenced, TypeRelationId, typeForm->typelem);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced,
 						   isImplicitArray ? DEPENDENCY_INTERNAL : DEPENDENCY_NORMAL);
 	}
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 738bc46ae8..a471833efe 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -367,6 +367,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		depLockAndCheckObject(&baseobject);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb447..e3ad5db529 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			depLockAndCheckObject(&refAddr);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc..0b4e44131a 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 78f96789b0..73bcd68a1f 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1381,6 +1381,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+				depLockAndCheckObject(&baseobject);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1389,6 +1390,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+				depLockAndCheckObject(&baseobject);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index 7a5ed6b985..ddcba91c92 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index 1643c8c69a..fdcffcea01 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -1935,7 +1935,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
-	record_object_address_dependencies(&myself, refobjs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, refobjs, DEPENDENCY_NORMAL);
 	free_object_addresses(refobjs);
 
 	/* Post creation hook for new extension */
@@ -3258,6 +3258,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			depLockAndCheckObject(&otherext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3414,6 +3415,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		depLockAndCheckObject(&extension);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1f..5e98f3d0d6 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 6593fd7d81..2a378a53d8 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1459,6 +1459,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1979,7 +1980,7 @@ CreateTransform(CreateTransformStmt *stmt)
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	/* dependency on extension */
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 309389e20d..487708d885 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4377,8 +4377,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			depLockAndCheckObject(&parentIdx);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			depLockAndCheckObject(&partitionTbl);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5..e7b1cb911e 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement here to ensure the new operator entry is
+		 * visible when we'll check of object existence when recording the
+		 * dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba824..5a50ad73fb 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	depLockAndCheckObject(&target);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	depLockAndCheckObject(&target);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017e..679155162e 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -205,7 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	/* Post creation hook for new procedural language */
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index 28f8522264..0d37576d22 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1681,6 +1681,7 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+		depLockAndCheckObject(&refobject);
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d2..455ec046f8 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -536,6 +536,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+		depLockAndCheckObject(&parentobject);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +554,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+		depLockAndCheckObject(&parentobject);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +575,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	depLockAndCheckObject(&parentobject);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 7b6c69b7a5..73696a4210 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3437,6 +3437,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	depLockAndCheckObject(&parentobject);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7440,6 +7441,7 @@ add_column_datatype_dependency(Oid relid, int32 attnum, Oid typid)
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 }
 
@@ -7461,6 +7463,7 @@ add_column_collation_dependency(Oid relid, int32 attnum, Oid collid)
 		referenced.classId = CollationRelationId;
 		referenced.objectId = collid;
 		referenced.objectSubId = 0;
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 }
@@ -10140,6 +10143,7 @@ addFkRecurseReferenced(List **wqueue, Constraint *fkconstraint, Relation rel,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
 	}
 
@@ -10431,8 +10435,10 @@ addFkRecurseReferencing(List **wqueue, Constraint *fkconstraint, Relation rel,
 			 */
 			ObjectAddressSet(address, ConstraintRelationId, constrOid);
 			ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, partitionId);
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 			/* Make all this visible before recursing */
@@ -10933,9 +10939,11 @@ CloneFkReferencing(List **wqueue, Relation parentRel, Relation partRel)
 		/* Set up partition dependencies for the new constraint */
 		ObjectAddressSet(address, ConstraintRelationId, constrOid);
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrOid);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(partRel));
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 		/* Done with the cloned constraint's tuple */
@@ -14782,6 +14790,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -16400,6 +16409,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	depLockAndCheckObject(&typeobj);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 95de402fa6..c0e7ddff1c 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1018,8 +1018,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1027,6 +1025,12 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement here to ensure the new trigger entry is visible
+	 * when we'll check of object existence when recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1045,6 +1049,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1058,6 +1063,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1070,6 +1076,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1077,6 +1084,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1091,6 +1099,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			depLockAndCheckObject(&myself);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1100,8 +1109,10 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1116,6 +1127,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+			depLockAndCheckObject(&referenced);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1255,9 +1267,11 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e..a62c997725 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -171,7 +171,7 @@ makeParserDependencies(HeapTuple tuple)
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	return myself;
@@ -329,7 +329,7 @@ makeDictionaryDependencies(HeapTuple tuple)
 	ObjectAddressSet(referenced, TSTemplateRelationId, dict->dicttemplate);
 	add_exact_object_address(&referenced, addrs);
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	return myself;
@@ -677,7 +677,7 @@ makeTSTemplateDependencies(HeapTuple tuple)
 		add_exact_object_address(&referenced, addrs);
 	}
 
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 	free_object_addresses(addrs);
 
 	return myself;
@@ -885,7 +885,7 @@ makeConfigurationDependencies(HeapTuple tuple, bool removeOld,
 	}
 
 	/* Record 'em (this includes duplicate elimination) */
-	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
+	lock_record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
 
 	free_object_addresses(addrs);
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a1e713335..cbb61c1207 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		depLockAndCheckObject(&referenced);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -1898,6 +1900,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 							 1.0,	/* procost */
 							 0.0);	/* prorows */
 	/* ditto */
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 	*castFuncOid = myself.objectId;
@@ -1936,6 +1939,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 							 1.0,	/* procost */
 							 0.0);	/* prorows */
 	/* ditto */
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 	pfree(allParameterTypes);
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bf..53308dceb6 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	depLockAndCheckObject(&referenced);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1..60e8539fe3 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 7eee66f810..f404a92fb4 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,8 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
+extern void depLockAndCheckObjects(const ObjectAddress *object, int nobject);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -128,9 +130,9 @@ extern void add_exact_object_address(const ObjectAddress *object,
 extern bool object_address_present(const ObjectAddress *object,
 								   const ObjectAddresses *addrs);
 
-extern void record_object_address_dependencies(const ObjectAddress *depender,
-											   ObjectAddresses *referenced,
-											   DependencyType behavior);
+extern void lock_record_object_address_dependencies(const ObjectAddress *depender,
+													ObjectAddresses *referenced,
+													DependencyType behavior);
 
 extern void sort_object_addresses(ObjectAddresses *addrs);
 
@@ -172,6 +174,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..56f746264b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 0342eb39e4..1b67f0bffe 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -114,3 +114,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-06 20:00                                           ` Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Robert Haas @ 2024-06-06 20:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Thu, Jun 6, 2024 at 1:56 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> v9 is more invasive (as it changes code in much more places) than v8 but it is
> easier to follow (as it is now clear where the new lock is acquired).

Hmm, this definitely isn't what I had in mind. Possibly that's a sign
that what I had in mind was dumb, but for sure it's not what I
imagined. What I thought you were going to do was add calls like
LockDatabaseObject(NamespaceRelationId, schemaid, 0, AccessShareLock)
in various places, or perhaps LockRelationOid(reloid,
AccessShareLock), or whatever the case may be. Here you've got stuff
like this:

- record_object_address_dependencies(&conobject, addrs_auto,
-    DEPENDENCY_AUTO);
+ lock_record_object_address_dependencies(&conobject, addrs_auto,
+ DEPENDENCY_AUTO);

...which to me looks like the locking is still pushed down inside the
dependency code.

And you also have stuff like this:

  ObjectAddressSet(referenced, RelationRelationId, childTableId);
+ depLockAndCheckObject(&referenced);
  recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);

But in depLockAndCheckObject you have:

+ if (object->classId == RelationRelationId || object->classId ==
AuthMemRelationId)
+ return;

That doesn't seem right, because then it seems like the call isn't
doing anything, but there isn't really any reason for it to not be
doing anything. If we're dropping a dependency on a table, then it
seems like we need to have a lock on that table. Presumably the reason
why we don't end up with dangling dependencies in such cases now is
because we're careful about doing LockRelation() in the right places,
but we're not similarly careful about other operations e.g.
ConstraintSetParentConstraint is called by DefineIndex which calls
table_open(childRelId, ...) first, but there's no logic in DefineIndex
to lock the constraint.

Thoughts?

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-06-07 08:41                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-07 08:41 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jun 06, 2024 at 04:00:23PM -0400, Robert Haas wrote:
> On Thu, Jun 6, 2024 at 1:56 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > v9 is more invasive (as it changes code in much more places) than v8 but it is
> > easier to follow (as it is now clear where the new lock is acquired).
> 
> Hmm, this definitely isn't what I had in mind. Possibly that's a sign
> that what I had in mind was dumb, but for sure it's not what I
> imagined. What I thought you were going to do was add calls like
> LockDatabaseObject(NamespaceRelationId, schemaid, 0, AccessShareLock)
> in various places, or perhaps LockRelationOid(reloid,
> AccessShareLock), or whatever the case may be.

I see what you’re saying, doing things like:

LockDatabaseObject(TypeRelationId, returnType, 0, AccessShareLock);
in ProcedureCreate() for example.

> Here you've got stuff
> like this:
> 
> - record_object_address_dependencies(&conobject, addrs_auto,
> -    DEPENDENCY_AUTO);
> + lock_record_object_address_dependencies(&conobject, addrs_auto,
> + DEPENDENCY_AUTO);
> 
> ...which to me looks like the locking is still pushed down inside the
> dependency code.

Yes but it’s now located in places where, I think, it’s easier to understand
what’s going on (as compare to v8), except maybe for:

recordDependencyOnExpr()
makeOperatorDependencies()
GenerateTypeDependencies()
makeParserDependencies()
makeDictionaryDependencies()
makeTSTemplateDependencies()
makeConfigurationDependencies()

but probably for:

heap_create_with_catalog()
StorePartitionKey()
index_create()
AggregateCreate()
CastCreate()
CreateConstraintEntry()
ProcedureCreate()
RangeCreate()
InsertExtensionTuple()
CreateTransform()
CreateProceduralLanguage()

The reasons I keep it linked to the dependency code are:

- To ensure we don’t miss anything (well, with the new Assert in place that’s
probably a tangential argument)

- It’s not only about locking the object: it’s also about 1) verifying the object
is pinned, 2) checking it still exists and 3) provide a description in the error
message if we can (in case the object does not exist anymore). Relying on an
already build object (in the dependency code) avoid to 1) define the object(s)
one more time or 2) create new functions that would do the same as isObjectPinned()
and getObjectDescription() with a different set of arguments.

That may sounds like weak arguments but it has been my reasoning.

Do you still find the code hard to maintain with v9?

> 
> And you also have stuff like this:
> 
>   ObjectAddressSet(referenced, RelationRelationId, childTableId);
> + depLockAndCheckObject(&referenced);
>   recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
> 
> But in depLockAndCheckObject you have:
> 
> + if (object->classId == RelationRelationId || object->classId ==
> AuthMemRelationId)
> + return;
> 
> That doesn't seem right, because then it seems like the call isn't
> doing anything, but there isn't really any reason for it to not be
> doing anything. If we're dropping a dependency on a table, then it
> seems like we need to have a lock on that table. Presumably the reason
> why we don't end up with dangling dependencies in such cases now is
> because we're careful about doing LockRelation() in the right places,

Yeah, that's what I think: we're already careful when we deal with relations.

> but we're not similarly careful about other operations e.g.
> ConstraintSetParentConstraint is called by DefineIndex which calls
> table_open(childRelId, ...) first, but there's no logic in DefineIndex
> to lock the constraint.

table_open(childRelId, ...) would lock any "ALTER TABLE <childRelId> DROP CONSTRAINT"
already. Not sure I understand your concern here.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-13 14:49                                               ` Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Robert Haas @ 2024-06-13 14:49 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Fri, Jun 7, 2024 at 4:41 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> Do you still find the code hard to maintain with v9?

I don't think it substantially changes my concerns as compared with
the earlier version.

> > but we're not similarly careful about other operations e.g.
> > ConstraintSetParentConstraint is called by DefineIndex which calls
> > table_open(childRelId, ...) first, but there's no logic in DefineIndex
> > to lock the constraint.
>
> table_open(childRelId, ...) would lock any "ALTER TABLE <childRelId> DROP CONSTRAINT"
> already. Not sure I understand your concern here.

I believe this is not true. This would take a lock on the table, not
the constraint itself.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-06-13 16:52                                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 10:50                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-13 16:52 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jun 13, 2024 at 10:49:34AM -0400, Robert Haas wrote:
> On Fri, Jun 7, 2024 at 4:41 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > Do you still find the code hard to maintain with v9?
> 
> I don't think it substantially changes my concerns as compared with
> the earlier version.

Thanks for the feedback, I'll give it more thoughts.

> 
> > > but we're not similarly careful about other operations e.g.
> > > ConstraintSetParentConstraint is called by DefineIndex which calls
> > > table_open(childRelId, ...) first, but there's no logic in DefineIndex
> > > to lock the constraint.
> >
> > table_open(childRelId, ...) would lock any "ALTER TABLE <childRelId> DROP CONSTRAINT"
> > already. Not sure I understand your concern here.
> 
> I believe this is not true. This would take a lock on the table, not
> the constraint itself.

I agree that it would not lock the constraint itself. What I meant to say is that
, nevertheless, the constraint can not be dropped. Indeed, the "ALTER TABLE"
necessary to drop the constraint (ALTER TABLE <childRelId> DROP CONSTRAINT) would
be locked by the table_open(childRelId, ...).

That's why I don't understand your concern with this particular example. But
anyway, I'll double check your related concern:

+ if (object->classId == RelationRelationId || object->classId ==
AuthMemRelationId)
+ return;

in depLockAndCheckObject(). 

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-13 18:27                                                   ` Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Robert Haas @ 2024-06-13 18:27 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Thu, Jun 13, 2024 at 12:52 PM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> > > table_open(childRelId, ...) would lock any "ALTER TABLE <childRelId> DROP CONSTRAINT"
> > > already. Not sure I understand your concern here.
> >
> > I believe this is not true. This would take a lock on the table, not
> > the constraint itself.
>
> I agree that it would not lock the constraint itself. What I meant to say is that
> , nevertheless, the constraint can not be dropped. Indeed, the "ALTER TABLE"
> necessary to drop the constraint (ALTER TABLE <childRelId> DROP CONSTRAINT) would
> be locked by the table_open(childRelId, ...).

Ah, right. So, I was assuming that, with either this version of your
patch or the earlier version, we'd end up locking the constraint
itself. Was I wrong about that?

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-06-14 07:54                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-14 07:54 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jun 13, 2024 at 02:27:45PM -0400, Robert Haas wrote:
> On Thu, Jun 13, 2024 at 12:52 PM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > > > table_open(childRelId, ...) would lock any "ALTER TABLE <childRelId> DROP CONSTRAINT"
> > > > already. Not sure I understand your concern here.
> > >
> > > I believe this is not true. This would take a lock on the table, not
> > > the constraint itself.
> >
> > I agree that it would not lock the constraint itself. What I meant to say is that
> > , nevertheless, the constraint can not be dropped. Indeed, the "ALTER TABLE"
> > necessary to drop the constraint (ALTER TABLE <childRelId> DROP CONSTRAINT) would
> > be locked by the table_open(childRelId, ...).
> 
> Ah, right. So, I was assuming that, with either this version of your
> patch or the earlier version, we'd end up locking the constraint
> itself. Was I wrong about that?

The child contraint itself is not locked when going through
ConstraintSetParentConstraint().

While at it, let's look at a full example and focus on your concern.

Let's do that with this gdb file:

"
$ cat gdb.txt
b dependency.c:1542
command 1
        printf "Will return for: classId %d and objectId %d\n", object->classId, object->objectId
        c
end
b dependency.c:1547 if object->classId == 2606
command 2
        printf "Will lock constraint: classId %d and objectId %d\n", object->classId, object->objectId
        c
end
"

knowing that:

"
Line 1542 is the return here in depLockAndCheckObject() (your concern):

    if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
        return;

Line 1547 is the lock here in depLockAndCheckObject():

    /* assume we should lock the whole object not a sub-object */
    LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
"

So, with gdb attached to a session let's:

1. Create the parent relation

CREATE TABLE upsert_test (
    a   INT,
    b   TEXT
) PARTITION BY LIST (a);

gdb produces:

---
Will return for: classId 1259 and objectId 16384
Will return for: classId 1259 and objectId 16384
---

Oid 16384 is upsert_test, so I think the return (dependency.c:1542) is fine as
we are creating the object (it can't be dropped as not visible to anyone else).

2. Create another relation (will be the child)

CREATE TABLE upsert_test_2 (b TEXT, a int);

gdb produces:

---
Will return for: classId 1259 and objectId 16391
Will return for: classId 1259 and objectId 16394
Will return for: classId 1259 and objectId 16394
Will return for: classId 1259 and objectId 16391
---

Oid 16391 is upsert_test_2
Oid 16394 is pg_toast_16391

so I think the return (dependency.c:1542) is fine as we are creating those
objects (can't be dropped as not visible to anyone else).

3. Attach the partition

ALTER TABLE upsert_test ATTACH PARTITION upsert_test_2 FOR VALUES IN (2);

gdb produces:

---
Will return for: classId 1259 and objectId 16384
---

That's fine because we'd already had locked the relation 16384 through
AlterTableLookupRelation()->RangeVarGetRelidExtended()->LockRelationOid().

4. Add a constraint on the child relation

ALTER TABLE upsert_test_2 add constraint bdtc2 UNIQUE (a);

gdb produces:

---
Will return for: classId 1259 and objectId 16391
Will lock constraint: classId 2606 and objectId 16397
---

That's fine because we'd already had locked the relation 16391 through
AlterTableLookupRelation()->RangeVarGetRelidExtended()->LockRelationOid().

Oid 16397 is the constraint we're creating (bdtc2).

5. Add a constraint on the parent relation (this goes through
ConstraintSetParentConstraint())

ALTER TABLE upsert_test add constraint bdtc1 UNIQUE (a);

gdb produces:

---
Will return for: classId 1259 and objectId 16384
Will lock constraint: classId 2606 and objectId 16399
Will return for: classId 1259 and objectId 16398
Will return for: classId 1259 and objectId 16391
Will lock constraint: classId 2606 and objectId 16399
Will return for: classId 1259 and objectId 16391
---

Regarding "Will return for: classId 1259 and objectId 16384":
That's fine because we'd already had locked the relation 16384 through
AlterTableLookupRelation()->RangeVarGetRelidExtended()->LockRelationOid().

Regarding "Will lock constraint: classId 2606 and objectId 16399":
Oid 16399 is the constraint that we're creating.

Regarding "Will return for: classId 1259 and objectId 16398":
That's fine because Oid 16398 is an index that we're creating while creating
the constraint (so the index can't be dropped as not visible to anyone else).

Regarding "Will return for: classId 1259 and objectId 16391":
That's fine because 16384 we'd be already locked (as mentioned above). And
I think that's fine because trying to drop "upsert_test_2" (aka 16391) would produce
RemoveRelations()->RangeVarGetRelidExtended()->RangeVarCallbackForDropRelation()
->LockRelationOid(relid=16384, lockmode=8) and so would be locked.

Regarding this example, I don't think that the return in depLockAndCheckObject():

"
if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
     return;
"

is an issue. Indeed, the example above shows it would return for an object that
we'd be creating (so not visible to anyone else) or for an object that we'd
already have locked.

Is it an issue outside of this example?: I've the feeling it's not as we're
already careful when we deal with relations. That said, to be on the safe side
we could get rid of this return and make use of LockRelationOid() instead.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-17 16:24                                                       ` Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Robert Haas @ 2024-06-17 16:24 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Fri, Jun 14, 2024 at 3:54 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> > Ah, right. So, I was assuming that, with either this version of your
> > patch or the earlier version, we'd end up locking the constraint
> > itself. Was I wrong about that?
>
> The child contraint itself is not locked when going through
> ConstraintSetParentConstraint().
>
> While at it, let's look at a full example and focus on your concern.

I'm not at the point of having a concern yet, honestly. I'm trying to
understand the design ideas. The commit message just says that we take
a conflicting lock, but it doesn't mention which object types that
principle does or doesn't apply to. I think the idea of skipping it
for cases where it's redundant with the relation lock could be the
right idea, but if that's what we're doing, don't we need to explain
the principle somewhere? And shouldn't we also apply it across all
object types that have the same property?

Along the same lines:

+ /*
+ * Those don't rely on LockDatabaseObject() when being dropped (see
+ * AcquireDeletionLock()). Also it looks like they can not produce
+ * orphaned dependent objects when being dropped.
+ */
+ if (object->classId == RelationRelationId || object->classId ==
AuthMemRelationId)
+ return;

"It looks like X cannot happen" is not confidence-inspiring. At the
very least, a better comment is needed here. But also, that relation
has no exception for AuthMemRelationId, only for RelationRelationId.
And also, the exception for RelationRelationId doesn't imply that we
don't need a conflicting lock here: the special case for
RelationRelationId in AcquireDeletionLock() is necessary because the
lock tag format is different for relations than for other database
objects, not because we don't need a lock at all. If the handling here
were really symmetric with what AcquireDeletionLock(), the coding
would be to call either LockRelationOid() or LockDatabaseObject()
depending on whether classid == RelationRelationId. Now, that isn't
actually necessary, because we already have relation-locking calls
elsewhere, but my point is that the rationale this commit gives for
WHY it isn't necessary seems to me to be wrong in multiple ways.

So to try to sum up here: I'm not sure I agree with this design. But I
also feel like the design is not as clear and consistently implemented
as it could be. So even if I just ignored the question of whether it's
the right design, it feels like we're a ways from having something
potentially committable here, because of issues like the ones I
mentioned in the last paragraph.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-06-17 17:57                                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 11:49                                                           ` Re: Avoid orphaned objects dependencies, take 3 Ashutosh Sharma <ashu.coek88@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-17 17:57 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Mon, Jun 17, 2024 at 12:24:46PM -0400, Robert Haas wrote:
> On Fri, Jun 14, 2024 at 3:54 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > > Ah, right. So, I was assuming that, with either this version of your
> > > patch or the earlier version, we'd end up locking the constraint
> > > itself. Was I wrong about that?
> >
> > The child contraint itself is not locked when going through
> > ConstraintSetParentConstraint().
> >
> > While at it, let's look at a full example and focus on your concern.
> 
> I'm not at the point of having a concern yet, honestly. I'm trying to
> understand the design ideas. The commit message just says that we take
> a conflicting lock, but it doesn't mention which object types that
> principle does or doesn't apply to. I think the idea of skipping it
> for cases where it's redundant with the relation lock could be the
> right idea, but if that's what we're doing, don't we need to explain
> the principle somewhere? And shouldn't we also apply it across all
> object types that have the same property?

Yeah, I still need to deeply study this area and document it. 

> Along the same lines:
> 
> + /*
> + * Those don't rely on LockDatabaseObject() when being dropped (see
> + * AcquireDeletionLock()). Also it looks like they can not produce
> + * orphaned dependent objects when being dropped.
> + */
> + if (object->classId == RelationRelationId || object->classId ==
> AuthMemRelationId)
> + return;
> 
> "It looks like X cannot happen" is not confidence-inspiring.

Yeah, it is not. It is just a "feeling" that I need to work on to remove
any ambiguity and/or adjust the code as needed.

> At the
> very least, a better comment is needed here. But also, that relation
> has no exception for AuthMemRelationId, only for RelationRelationId.
> And also, the exception for RelationRelationId doesn't imply that we
> don't need a conflicting lock here: the special case for
> RelationRelationId in AcquireDeletionLock() is necessary because the
> lock tag format is different for relations than for other database
> objects, not because we don't need a lock at all. If the handling here
> were really symmetric with what AcquireDeletionLock(), the coding
> would be to call either LockRelationOid() or LockDatabaseObject()
> depending on whether classid == RelationRelationId.

Agree.

> Now, that isn't
> actually necessary, because we already have relation-locking calls
> elsewhere, but my point is that the rationale this commit gives for
> WHY it isn't necessary seems to me to be wrong in multiple ways.

Agree. I'm not done with that part yet (should have made it more clear).

> So to try to sum up here: I'm not sure I agree with this design. But I
> also feel like the design is not as clear and consistently implemented
> as it could be. So even if I just ignored the question of whether it's
> the right design, it feels like we're a ways from having something
> potentially committable here, because of issues like the ones I
> mentioned in the last paragraph.
> 

Agree. I'll now move on with the "XXX Do we need a lock for RelationRelationId?"
comments that I put in v10 (see [1]) and study all the cases around them.

Once done, I think that it will easier to 1.remove ambiguity, 2.document and
3.do the "right" thing regarding the RelationRelationId object class.

[1]: https://www.postgresql.org/message-id/ZnAVEBhlGvpDDVOD%40ip-10-97-1-34.eu-west-3.compute.internal

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-19 11:49                                                           ` Ashutosh Sharma <ashu.coek88@gmail.com>
  2024-06-19 12:20                                                             ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Ashutosh Sharma @ 2024-06-19 11:49 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Robert Haas <robertmhaas@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

If the dependency is more, this can hit max_locks_per_transaction
limit very fast. Won't it? I just tried this little experiment with
and without patch.

1) created some UDTs (I have just chosen some random number, 15)
do $$
declare
    i int := 1;
    type_name text;
begin
    while i <= 15 loop
        type_name := format('ct_%s', i);

        -- check if the type already exists
        if not exists (
            select 1
            from pg_type
            where typname = type_name
        ) then
            execute format('create type %I as (f1 INT, f2 TEXT);', type_name);
        end if;

        i := i + 1;
    end loop;
end $$;

2) started a transaction and tried creating a table that uses all udts
created above:
begin;
create table dep_tab(a ct_1, b ct_2, c ct_3, d ct_4, e ct_5, f ct_6, g
ct_7, h ct_8, i ct_9, j ct_10, k ct_11, l ct_12, m ct_13, n ct_14, o
ct_15);

3) checked the pg_locks entries inside the transaction both with and
without patch:

-- with patch:
select count(*) from pg_locks;
 count
-------
    23
(1 row)

-- without patch:
select count(*) from pg_locks;
 count
-------
     7
(1 row)

With patch, it increased by 3 times. Won't that create a problem if
many concurrent sessions engage in similar activity?

--
With Regards,
Ashutosh Sharma.





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 11:49                                                           ` Re: Avoid orphaned objects dependencies, take 3 Ashutosh Sharma <ashu.coek88@gmail.com>
@ 2024-06-19 12:20                                                             ` Robert Haas <robertmhaas@gmail.com>
  2024-06-19 13:35                                                               ` Re: Avoid orphaned objects dependencies, take 3 Ashutosh Sharma <ashu.coek88@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Robert Haas @ 2024-06-19 12:20 UTC (permalink / raw)
  To: Ashutosh Sharma <ashu.coek88@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

On Wed, Jun 19, 2024 at 7:49 AM Ashutosh Sharma <ashu.coek88@gmail.com> wrote:
> If the dependency is more, this can hit max_locks_per_transaction
> limit very fast.

Your experiment doesn't support this conclusion. Very few users would
have 15 separate user-defined types in the same table, and even if
they did, and dropped the table, using 23 locks is no big deal. By
default, max_locks_per_transaction is 64, so the user would need to
have more like 45 separate user-defined types in the same table in
order to use more than 64 locks. So, yes, it is possible that if every
backend in the system were simultaneously trying to drop a table and
all of those tables had an average of at least 45 or so user-defined
types, all different from each other, you might run out of lock table
space.

But probably nobody will ever do that in real life, and if they did,
they could just raise max_locks_per_transaction.

When posting about potential problems like this, it is a good idea to
first do a careful thought experiment to assess how realistic the
problem is. I would consider an issue like this serious if there were
a realistic scenario under which a small number of backends could
exhaust the lock table for the whole system, but I think you can see
that this isn't the case here. Even your original scenario is more
extreme than what most people are likely to hit in real life, and it
only uses 23 locks.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 11:49                                                           ` Re: Avoid orphaned objects dependencies, take 3 Ashutosh Sharma <ashu.coek88@gmail.com>
  2024-06-19 12:20                                                             ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2024-06-19 13:35                                                               ` Ashutosh Sharma <ashu.coek88@gmail.com>
  0 siblings, 0 replies; 93+ messages in thread

From: Ashutosh Sharma @ 2024-06-19 13:35 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: pgsql-hackers@lists.postgresql.org

Hi Robert,

On Wed, Jun 19, 2024 at 5:50 PM Robert Haas <robertmhaas@gmail.com> wrote:
>
> On Wed, Jun 19, 2024 at 7:49 AM Ashutosh Sharma <ashu.coek88@gmail.com> wrote:
> > If the dependency is more, this can hit max_locks_per_transaction
> > limit very fast.
>
> Your experiment doesn't support this conclusion. Very few users would
> have 15 separate user-defined types in the same table, and even if
> they did, and dropped the table, using 23 locks is no big deal. By
> default, max_locks_per_transaction is 64, so the user would need to
> have more like 45 separate user-defined types in the same table in
> order to use more than 64 locks. So, yes, it is possible that if every
> backend in the system were simultaneously trying to drop a table and
> all of those tables had an average of at least 45 or so user-defined
> types, all different from each other, you might run out of lock table
> space.
>
> But probably nobody will ever do that in real life, and if they did,
> they could just raise max_locks_per_transaction.
>
> When posting about potential problems like this, it is a good idea to
> first do a careful thought experiment to assess how realistic the
> problem is. I would consider an issue like this serious if there were
> a realistic scenario under which a small number of backends could
> exhaust the lock table for the whole system, but I think you can see
> that this isn't the case here. Even your original scenario is more
> extreme than what most people are likely to hit in real life, and it
> only uses 23 locks.
>

I agree that based on the experiment I shared (which is somewhat
unrealistic), this doesn't seem to have any significant implications.
However, I was concerned that it could potentially increase the usage
of max_locks_per_transaction, which is why I wanted to mention it
here. Nonetheless, my experiment did not reveal any serious issues
related to this. Sorry for the noise.

--
With Regards,
Ashutosh Sharma.





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-19 14:11                                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-19 14:11 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Mon, Jun 17, 2024 at 05:57:05PM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Mon, Jun 17, 2024 at 12:24:46PM -0400, Robert Haas wrote:
> > So to try to sum up here: I'm not sure I agree with this design. But I
> > also feel like the design is not as clear and consistently implemented
> > as it could be. So even if I just ignored the question of whether it's
> > the right design, it feels like we're a ways from having something
> > potentially committable here, because of issues like the ones I
> > mentioned in the last paragraph.
> > 
> 
> Agree. I'll now move on with the "XXX Do we need a lock for RelationRelationId?"
> comments that I put in v10 (see [1]) and study all the cases around them.

A. I went through all of them, did some testing for all, and reached the
conclusion that we must be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends of
the table...).

So we don't need to add a lock if this is a RelationRelationId object class for
the cases above.

As a consequence, I replaced the "XXX" related comments that were in v10 by
another set of comments in v11 (attached) like "No need to call LockRelationOid()
(through LockNotPinnedObject())....". Reason is to make it clear in the code
and also to ease the review.

B. I explained in [1] (while sharing v10) that the object locking is now outside
of the dependency code except for (and I explained why):

recordDependencyOnExpr() 
recordDependencyOnSingleRelExpr()
makeConfigurationDependencies()

So I also did some testing, on the RelationRelationId case, for those and I
reached the same conclusion as the one shared above.

For A. and B. the testing has been done by adding a "ereport(WARNING.." at
those places when a RelationRelationId is involved. Then I run "make check"
and went to the failed tests (output were not the expected ones due to the
extra "WARNING"), reproduced them with gdb and checked for the lock on the
relation producing the "WARNING". All of those were linked to 1. or 2.

Note that adding an assertion on an existing lock would not work for the cases
described in 2.

So, I'm now confident that we must be in 1. or 2. but it's also possible
that I've missed some cases (though I think the way the testing has been done is
not that weak).

To sum up, I did not see any cases that did not lead to 1. or 2., so I think
it's safe to not add an extra lock for the RelationRelationId case. If, for any
reason, there is still cases that are outside 1. or 2. then they may lead to
orphaned dependencies linked to the RelationRelationId class. I think that's
fine to take that "risk" given that a. that would not be worst than currently
and b. I did not see any of those in our fleet currently (while I have seen a non
negligible amount outside of the RelationRelationId case).

> Once done, I think that it will easier to 1.remove ambiguity, 2.document and
> 3.do the "right" thing regarding the RelationRelationId object class.
> 

Please find attached v11, where I added more detailed comments in the commit
message and also in the code (I also removed the useless check on
AuthMemRelationId).

[1]: https://www.postgresql.org/message-id/ZnAVEBhlGvpDDVOD%40ip-10-97-1-34.eu-west-3.compute.internal

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v11-0001-Avoid-orphaned-objects-dependencies.patch (96.9K, ../../ZnLnJhFOBGoz7GD3@ip-10-97-1-34.eu-west-3.compute.internal/2-v11-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 50e11432960e0ad5d940d2e7d9557fc4770d8262 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v11] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch takes into account any type of objects except:

- the ones that are pinned
- the ones that belongs to the RelationRelationId class

For the former, that's due to the fact that pinned objects are not droppable
because the system requires it.

For the later, that because we must be in one of the two following cases that
would already prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends the table...)

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 115 +++++++++++++++-
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  40 ++++++
 src/backend/catalog/objectaddress.c           |  57 ++++++++
 src/backend/catalog/pg_aggregate.c            |   9 ++
 src/backend/catalog/pg_attrdef.c              |   4 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  37 +++++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  26 +++-
 src/backend/catalog/pg_operator.c             |  19 +++
 src/backend/catalog/pg_proc.c                 |  17 ++-
 src/backend/catalog/pg_publication.c          |  13 ++
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  38 ++++++
 src/backend/catalog/toasting.c                |   4 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |  13 ++
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 +++
 src/backend/commands/operatorcmds.c           |  30 ++++
 src/backend/commands/policy.c                 |   8 ++
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   5 +
 src/backend/commands/statscmds.c              |  11 ++
 src/backend/commands/tablecmds.c              |  43 ++++--
 src/backend/commands/trigger.c                |  39 +++++-
 src/backend/commands/tsearchcmds.c            |  81 +++++++----
 src/backend/commands/typecmds.c               |  84 ++++++++++++
 src/backend/rewrite/rewriteDefine.c           |   4 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   7 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 43 files changed, 947 insertions(+), 47 deletions(-)
  33.4% src/backend/catalog/
  36.6% src/backend/commands/
  17.1% src/test/isolation/expected/
  10.6% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 143876b77f..5a614f25ff 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1413,6 +1413,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 0489cbabcb..b779872c3e 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,90 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	if (isObjectPinned(object))
+		return;
+
+	/*
+	 * We must be in one of the two following cases that would already prevent
+	 * the relation to be dropped: 1. The relation is already locked (could be
+	 * an existing relation or a relation that we are creating). 2. The
+	 * relation is protected indirectly (i.e an index protected by a lock on
+	 * its table, a table protected by a lock on a function that depends of
+	 * the table...). So don't add a lock if this is a RelationRelationId
+	 * object class (would need to make use of LockRelationOid() though). Note
+	 * that, due to 2., adding an assertion that we already hold a lock on the
+	 * relation is not doable.
+	 */
+	if (object->classId == RelationRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+void
+LockNotPinnedObjectsById(const ObjectAddress *object, int nobject)
+{
+	int			i;
+
+	if (nobject < 0)
+		return;
+
+	for (i = 0; i < nobject; i++, object++)
+		LockNotPinnedObjectById(object);
+
+	return;
+}
+
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1564,13 +1648,8 @@ recordDependencyOnExpr(const ObjectAddress *depender,
 	/* Scan the expression tree for referenceable objects */
 	find_expr_references_walker(expr, &context);
 
-	/* Remove any duplicates */
-	eliminate_duplicate_dependencies(context.addrs);
-
-	/* And record 'em */
-	recordMultipleDependencies(depender,
-							   context.addrs->refs, context.addrs->numrefs,
-							   behavior);
+	/* Record all of them (this includes duplicate elimination) */
+	lock_record_object_address_dependencies(depender, context.addrs, behavior);
 
 	free_object_addresses(context.addrs);
 }
@@ -1654,14 +1733,19 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 
 		/* Record the self-dependencies with the appropriate direction */
 		if (!reverse_self)
+		{
+			LockNotPinnedObjectsById(self_addrs->refs, self_addrs->numrefs);
 			recordMultipleDependencies(depender,
 									   self_addrs->refs, self_addrs->numrefs,
 									   self_behavior);
+		}
 		else
 		{
 			/* Can't use recordMultipleDependencies, so do it the hard way */
 			int			selfref;
 
+			LockNotPinnedObjectById(depender);
+
 			for (selfref = 0; selfref < self_addrs->numrefs; selfref++)
 			{
 				ObjectAddress *thisobj = self_addrs->refs + selfref;
@@ -1674,6 +1758,7 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 	}
 
 	/* Record the external dependencies */
+	LockNotPinnedObjectsById(context.addrs->refs, context.addrs->numrefs);
 	recordMultipleDependencies(depender,
 							   context.addrs->refs, context.addrs->numrefs,
 							   behavior);
@@ -2734,6 +2819,22 @@ stack_address_present_add_flags(const ObjectAddress *object,
 	return result;
 }
 
+/*
+ * Record multiple dependencies from an ObjectAddresses array and lock the
+ * referenced objects, after first removing any duplicates.
+ */
+void
+lock_record_object_address_dependencies(const ObjectAddress *depender,
+										ObjectAddresses *referenced,
+										DependencyType behavior)
+{
+	eliminate_duplicate_dependencies(referenced);
+	LockNotPinnedObjectsById(referenced->refs, referenced->numrefs);
+	recordMultipleDependencies(depender,
+							   referenced->refs, referenced->numrefs,
+							   behavior);
+}
+
 /*
  * Record multiple dependencies from an ObjectAddresses array, after first
  * removing any duplicates.
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index a122bbffce..00977e56c4 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -843,6 +843,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId,
 						 tupdesc->attrs[i].atttypid);
+		LockNotPinnedObject(TypeRelationId, tupdesc->attrs[i].atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -851,6 +852,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 tupdesc->attrs[i].attcollation);
+			LockNotPinnedObject(CollationRelationId, tupdesc->attrs[i].attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1451,11 +1453,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1469,6 +1473,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3383,6 +3388,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3390,6 +3396,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index 55fdde4b24..445ea5a846 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1127,6 +1127,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					/*
+					 * No need to call LockRelationOid() (through
+					 * LockNotPinnedObject()) on heapRelationId as it is
+					 * already locked.
+					 */
 					have_simple_col = true;
 				}
 			}
@@ -1142,6 +1148,12 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				/*
+				 * No need to call LockRelationOid() (through
+				 * LockNotPinnedObject()) on heapRelationId as it is already
+				 * locked.
+				 */
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1157,9 +1169,21 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			/*
+			 * No need to call LockRelationOid() (through
+			 * LockNotPinnedObject()) on parentIndexRelid as it is already
+			 * locked.
+			 */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			/*
+			 * No need to call LockRelationOid() (through
+			 * LockNotPinnedObject()) on heapRelationId as it is already
+			 * locked.
+			 */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1175,6 +1199,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1183,6 +1208,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1987,6 +2013,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -1998,9 +2032,15 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on heapRelation as it is already locked.
+		 */
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..6d7abd3738 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949..a47e3c5507 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d..21491613e3 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,10 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	/*
+	 * No need to call LockRelationOid() (through LockNotPinnedObject()) on
+	 * rel as it is already locked.
+	 */
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d51..d3707e424c 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f701229..78498b8c20 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 3baf9231ed..c7c1115bec 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -257,12 +257,22 @@ CreateConstraintEntry(const char *constraintName,
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				/*
+				 * No need to call LockRelationOid() (through
+				 * LockNotPinnedObject()) on relId as it is already locked.
+				 */
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+
+			/*
+			 * No need to call LockRelationOid() (through
+			 * LockNotPinnedObject()) on relId as it is already locked.
+			 */
 		}
 	}
 
@@ -275,6 +285,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -299,12 +310,23 @@ CreateConstraintEntry(const char *constraintName,
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				/*
+				 * No need to call LockRelationOid() (through
+				 * LockNotPinnedObject()) on foreignRelId as it is already
+				 * locked.
+				 */
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+
+			/*
+			 * No need to call LockRelationOid() (through
+			 * LockNotPinnedObject()) on foreignRelId as it is already locked.
+			 */
 		}
 	}
 
@@ -320,6 +342,12 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on indexRelId as it can't be dropped as its table is already
+		 * locked.
+		 */
 	}
 
 	if (foreignNKeys > 0)
@@ -339,15 +367,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -858,9 +889,15 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on childTableId as it is already locked.
+		 */
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac..25881654d6 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index cfd7ef51df..f6f9764ec9 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,21 +20,20 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
-
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
  * The first argument is the dependent object, the second the one it
@@ -100,6 +99,24 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		LOCKTAG		tag;
+
+		SET_LOCKTAG_OBJECT(tag,
+						   MyDatabaseId,
+						   referenced->classId,
+						   referenced->objectId,
+						   0);
+
+		/*
+		 * Assert the referenced object is locked (see
+		 * LockNotPinnedObjectById()).
+		 */
+		Assert(isObjectPinned(referenced) ||
+			   referenced->classId == RelationRelationId ||
+			   LockHeldByMe(&tag, AccessShareLock));
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -239,6 +256,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -706,7 +724,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a..e8374eec88 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f..116e524390 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 0602398a54..e546c0a6fa 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -438,10 +438,16 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	/*
+	 * No need to call LockRelationOid() (through LockNotPinnedObject()) on
+	 * relid as it is already locked.
+	 */
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -454,6 +460,11 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	for (int i = 0; i < natts; i++)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, attarray[i]);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relid as it is already locked.
+		 */
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -661,10 +672,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba410..e5b5a0b6f8 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed8..5b36ff383a 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,36 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid.
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +542,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 738bc46ae8..6705bc24b8 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -367,6 +367,10 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relOid as it is already locked.
+		 */
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb447..57e86f576a 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -807,6 +810,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc..8616a7c9fa 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 78f96789b0..5d8b2948d8 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1272,6 +1272,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1280,6 +1281,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1381,6 +1384,11 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				/*
+				 * No need to call LockRelationOid() (through
+				 * LockNotPinnedObject()) on r1 as it is already locked.
+				 */
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1389,6 +1397,11 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				/*
+				 * No need to call LockRelationOid() (through
+				 * LockNotPinnedObject()) on r2 as it is already locked.
+				 */
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index 7a5ed6b985..8d0cdec59e 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index 1643c8c69a..669a5d6dd8 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -1924,6 +1924,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -1932,6 +1933,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -2968,6 +2970,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3258,6 +3261,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3414,6 +3418,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1f..735bca486c 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 6593fd7d81..8207ef08b3 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1446,6 +1446,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1459,6 +1460,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1962,21 +1964,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 309389e20d..b14eaad7a3 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4377,8 +4377,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			/* Do we lock for RelationRelationId?? */
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			/* Do we lock for RelationRelationId?? */
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5..e70afd216c 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 5872a3e192..58a69e7cc2 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba824..f04e87ee5d 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,10 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	/*
+	 * No need to call LockRelationOid() (through LockNotPinnedObject()) on
+	 * table_id as it is already locked.
+	 */
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1057,10 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	/*
+	 * No need to call LockRelationOid() (through LockNotPinnedObject()) on
+	 * table_id as it is already locked.
+	 */
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017e..fadfd9064f 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index 28f8522264..80c23d98a5 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1681,6 +1681,11 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on tablerel as it is already locked.
+		 */
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d2..23a34aeb79 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -536,6 +536,11 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relid as it is already locked.
+		 */
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +558,11 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relid as it is already locked.
+		 */
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +583,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 66cda26a25..4b5fcca399 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3438,6 +3438,10 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	/*
+	 * No need to call LockRelationOid() (through LockNotPinnedObject()) on
+	 * parentOid as it is already locked.
+	 */
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7349,7 +7353,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10174,6 +10180,7 @@ addFkRecurseReferenced(List **wqueue, Constraint *fkconstraint, Relation rel,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+		LockNotPinnedObject(ConstraintRelationId, parentConstr);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
 	}
 
@@ -10465,8 +10472,14 @@ addFkRecurseReferencing(List **wqueue, Constraint *fkconstraint, Relation rel,
 			 */
 			ObjectAddressSet(address, ConstraintRelationId, constrOid);
 			ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, partitionId);
+
+			/*
+			 * No need to call LockRelationOid() (through
+			 * LockNotPinnedObject()) on partitionId as it is already locked.
+			 */
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 			/* Make all this visible before recursing */
@@ -10967,9 +10980,15 @@ CloneFkReferencing(List **wqueue, Relation parentRel, Relation partRel)
 		/* Set up partition dependencies for the new constraint */
 		ObjectAddressSet(address, ConstraintRelationId, constrOid);
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrOid);
+		LockDatabaseObject(ConstraintRelationId, parentConstrOid, 0, AccessShareLock);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(partRel));
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on partRel as it is already locked.
+		 */
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 		/* Done with the cloned constraint's tuple */
@@ -13254,7 +13273,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -14816,6 +14837,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -14835,6 +14857,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -16434,6 +16457,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17192,14 +17216,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 		CatalogTupleUpdate(classRel, &classTup->t_self, classTup);
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
-								relOid,
-								NamespaceRelationId,
-								oldNspOid,
-								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
+									relOid,
+									NamespaceRelationId,
+									oldNspOid,
+									newNspOid) != 1)
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	if (!already_done)
 	{
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 95de402fa6..99433cce75 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1018,8 +1018,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1027,6 +1025,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1045,6 +1050,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1058,6 +1064,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1070,6 +1077,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on rel as it is already locked.
+		 */
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1077,6 +1089,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			/*
+			 * No need to call LockRelationOid() (through
+			 * LockNotPinnedObject()) on constrrelid as it is already locked.
+			 */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1091,6 +1108,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1100,8 +1118,14 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			/*
+			 * No need to call LockRelationOid() (through
+			 * LockNotPinnedObject()) on rel as it is already locked.
+			 */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1116,6 +1140,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			/*
+			 * No need to call LockRelationOid() (through
+			 * LockNotPinnedObject()) on rel as it is already locked.
+			 */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1255,9 +1284,15 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on childTableId as it is already locked.
+		 */
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e..29e02f4946 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -66,12 +66,12 @@ static DefElem *buildDefItem(const char *name, const char *val,
 /* --------------------- TS Parser commands ------------------------ */
 
 /*
- * lookup a parser support function and return its OID (as a Datum)
+ * lookup a parser support function and return its OID
  *
  * attnum is the pg_ts_parser column the function will go into
  */
-static Datum
-get_ts_parser_func(DefElem *defel, int attnum)
+static Oid
+get_ts_parser_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[3];
@@ -125,7 +125,7 @@ get_ts_parser_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,38 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
-			values[Anum_pg_ts_parser_prsstart - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsstart);
+
+			values[Anum_pg_ts_parser_prsstart - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
-			values[Anum_pg_ts_parser_prstoken - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prstoken);
+
+			values[Anum_pg_ts_parser_prstoken - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
-			values[Anum_pg_ts_parser_prsend - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsend);
+
+			values[Anum_pg_ts_parser_prsend - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
-			values[Anum_pg_ts_parser_prsheadline - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsheadline);
+
+			values[Anum_pg_ts_parser_prsheadline - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
-			values[Anum_pg_ts_parser_prslextype - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prslextype);
+
+			values[Anum_pg_ts_parser_prslextype - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +485,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -601,12 +616,12 @@ AlterTSDictionary(AlterTSDictionaryStmt *stmt)
 /* ---------------------- TS Template commands -----------------------*/
 
 /*
- * lookup a template support function and return its OID (as a Datum)
+ * lookup a template support function and return its OID
  *
  * attnum is the pg_ts_template column the function will go into
  */
-static Datum
-get_ts_template_func(DefElem *defel, int attnum)
+static Oid
+get_ts_template_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[4];
@@ -642,7 +657,7 @@ get_ts_template_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -723,6 +738,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +749,19 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
-			values[Anum_pg_ts_template_tmplinit - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmplinit);
+
+			values[Anum_pg_ts_template_tmplinit - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
-			values[Anum_pg_ts_template_tmpllexize - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmpllexize);
+
+			values[Anum_pg_ts_template_tmpllexize - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -879,6 +899,7 @@ makeConfigurationDependencies(HeapTuple tuple, bool removeOld,
 			referenced.objectId = cfgmap->mapdict;
 			referenced.objectSubId = 0;
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 		}
 
 		systable_endscan(scan);
@@ -998,6 +1019,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1156,6 +1181,7 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
@@ -1168,7 +1194,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1210,10 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1445,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1489,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a1e713335..9febaa24a7 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2672,6 +2674,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4276,10 +4317,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4571,6 +4615,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4619,6 +4664,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bf..06f6c952e3 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,10 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	/*
+	 * No need to call LockRelationOid() (through LockNotPinnedObject()) on
+	 * eventrel_oid as it is already locked.
+	 */
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1..60e8539fe3 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 7eee66f810..c57204cc40 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,9 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObjectsById(const ObjectAddress *object, int nobject);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -128,6 +131,9 @@ extern void add_exact_object_address(const ObjectAddress *object,
 extern bool object_address_present(const ObjectAddress *object,
 								   const ObjectAddresses *addrs);
 
+extern void lock_record_object_address_dependencies(const ObjectAddress *depender,
+													ObjectAddresses *referenced,
+													DependencyType behavior);
 extern void record_object_address_dependencies(const ObjectAddress *depender,
 											   ObjectAddresses *referenced,
 											   DependencyType behavior);
@@ -172,6 +178,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..56f746264b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 0342eb39e4..1b67f0bffe 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -114,3 +114,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-21 13:22                                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-21 13:22 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, Jun 19, 2024 at 02:11:50PM +0000, Bertrand Drouvot wrote:
> To sum up, I did not see any cases that did not lead to 1. or 2., so I think
> it's safe to not add an extra lock for the RelationRelationId case. If, for any
> reason, there is still cases that are outside 1. or 2. then they may lead to
> orphaned dependencies linked to the RelationRelationId class. I think that's
> fine to take that "risk" given that a. that would not be worst than currently
> and b. I did not see any of those in our fleet currently (while I have seen a non
> negligible amount outside of the RelationRelationId case).

Another thought for the RelationRelationId class case: we could check if there
is a lock first and if there is no lock then acquire one. That way that would
ensure the relation is always locked (so no "risk" anymore), but OTOH it may
add "unecessary" locking (see 2. mentioned previously).

I think I do prefer this approach to be on the safe side of thing, what do
you think?

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-26 10:24                                                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-01 09:39                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-26 10:24 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Fri, Jun 21, 2024 at 01:22:43PM +0000, Bertrand Drouvot wrote:
> Another thought for the RelationRelationId class case: we could check if there
> is a lock first and if there is no lock then acquire one. That way that would
> ensure the relation is always locked (so no "risk" anymore), but OTOH it may
> add "unecessary" locking (see 2. mentioned previously).

Please find attached v12 implementing this idea for the RelationRelationId class
case. As mentioned, it may add unnecessary locking for 2. but I think that's
worth it to ensure that we are always on the safe side of thing. This idea is
implemented in LockNotPinnedObjectById().

A few remarks:

- there is one place where the relation is not visible (even if
CommandCounterIncrement() is used). That's in TypeCreate(), because the new 
relation Oid is _not_ added to pg_class yet.
Indeed, in heap_create_with_catalog(), AddNewRelationType() is called before
AddNewRelationTuple()). I put a comment in this part of the code explaining why
it's not necessary to call LockRelationOid() here.

- some namespace related stuff is removed from "test_oat_hooks/expected/alter_table.out".
That's due to the logic in cachedNamespacePath() and the fact that the same
namespace related stuff is added prior in alter_table.out.

- the patch touches 37 .c files, but that's mainly due to the fact that
LockNotPinnedObjectById() has to be called in a lot of places.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v12-0001-Avoid-orphaned-objects-dependencies.patch (101.8K, ../../ZnvsaVGqd4wI9vJ+@ip-10-97-1-34.eu-west-3.compute.internal/2-v12-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From d6c91b19a585d0a6f5c0abacb9c59cc5acd795f7 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v12] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch takes into account any type of objects except the ones that are pinned
(they are not droppable because the system requires it).

A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that's worth it.

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 contrib/test_decoding/expected/twophase.out   |   3 +-
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 125 ++++++++++++++++-
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  26 ++++
 src/backend/catalog/objectaddress.c           |  57 ++++++++
 src/backend/catalog/pg_aggregate.c            |   9 ++
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  26 ++++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  36 ++++-
 src/backend/catalog/pg_operator.c             |  19 +++
 src/backend/catalog/pg_proc.c                 |  17 ++-
 src/backend/catalog/pg_publication.c          |   7 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  39 ++++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   7 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 +++
 src/backend/commands/operatorcmds.c           |  30 ++++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   2 +
 src/backend/commands/statscmds.c              |  10 ++
 src/backend/commands/tablecmds.c              |  34 +++--
 src/backend/commands/trigger.c                |  29 +++-
 src/backend/commands/tsearchcmds.c            |  81 +++++++----
 src/backend/commands/typecmds.c               |  84 ++++++++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   7 +
 src/include/catalog/objectaddress.h           |   1 +
 src/include/storage/lock.h                    |   9 ++
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 .../test_oat_hooks/expected/alter_table.out   |   4 +-
 .../expected/test_oat_hooks.out               |   2 +
 src/test/regress/expected/alter_table.out     |  11 +-
 48 files changed, 914 insertions(+), 55 deletions(-)
  32.8% src/backend/catalog/
  34.6% src/backend/commands/
  17.1% src/test/isolation/expected/
  10.7% src/test/isolation/specs/
   4.3% src/

diff --git a/contrib/test_decoding/expected/twophase.out b/contrib/test_decoding/expected/twophase.out
index 517f20bc37..71581fba34 100644
--- a/contrib/test_decoding/expected/twophase.out
+++ b/contrib/test_decoding/expected/twophase.out
@@ -69,9 +69,10 @@ WHERE locktype = 'relation'
   AND relation = 'test_prepared1'::regclass;
     relation     | locktype |        mode         
 -----------------+----------+---------------------
+ test_prepared_1 | relation | AccessShareLock
  test_prepared_1 | relation | RowExclusiveLock
  test_prepared_1 | relation | AccessExclusiveLock
-(2 rows)
+(3 rows)
 
 -- The insert should show the newly altered column but not the DDL.
 SELECT data FROM pg_logical_slot_get_changes('regression_slot', NULL, NULL, 'include-xids', '0', 'skip-empty-xacts', '1');
diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index a44ccee3b6..9a24872a30 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1413,6 +1413,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 0489cbabcb..782bdb580e 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,100 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description = NULL;
+
+	if (isObjectPinned(object))
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	if (object->classId == RelationRelationId)
+	{
+		LOCKTAG		tag;
+
+		Assert(!IsSharedRelation(object->objectId));
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		SET_LOCKTAG_RELATION(tag, MyDatabaseId, object->objectId);
+
+		if (!ObjectIsLocked(&tag))
+			LockRelationOid(object->objectId, AccessShareLock);
+	}
+	else
+	{
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+void
+LockNotPinnedObjectsById(const ObjectAddress *object, int nobject)
+{
+	int			i;
+
+	if (nobject < 0)
+		return;
+
+	for (i = 0; i < nobject; i++, object++)
+		LockNotPinnedObjectById(object);
+
+	return;
+}
+
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1564,13 +1658,8 @@ recordDependencyOnExpr(const ObjectAddress *depender,
 	/* Scan the expression tree for referenceable objects */
 	find_expr_references_walker(expr, &context);
 
-	/* Remove any duplicates */
-	eliminate_duplicate_dependencies(context.addrs);
-
-	/* And record 'em */
-	recordMultipleDependencies(depender,
-							   context.addrs->refs, context.addrs->numrefs,
-							   behavior);
+	/* Record all of them (this includes duplicate elimination) */
+	lock_record_object_address_dependencies(depender, context.addrs, behavior);
 
 	free_object_addresses(context.addrs);
 }
@@ -1654,14 +1743,19 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 
 		/* Record the self-dependencies with the appropriate direction */
 		if (!reverse_self)
+		{
+			LockNotPinnedObjectsById(self_addrs->refs, self_addrs->numrefs);
 			recordMultipleDependencies(depender,
 									   self_addrs->refs, self_addrs->numrefs,
 									   self_behavior);
+		}
 		else
 		{
 			/* Can't use recordMultipleDependencies, so do it the hard way */
 			int			selfref;
 
+			LockNotPinnedObjectById(depender);
+
 			for (selfref = 0; selfref < self_addrs->numrefs; selfref++)
 			{
 				ObjectAddress *thisobj = self_addrs->refs + selfref;
@@ -1674,6 +1768,7 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 	}
 
 	/* Record the external dependencies */
+	LockNotPinnedObjectsById(context.addrs->refs, context.addrs->numrefs);
 	recordMultipleDependencies(depender,
 							   context.addrs->refs, context.addrs->numrefs,
 							   behavior);
@@ -2734,6 +2829,22 @@ stack_address_present_add_flags(const ObjectAddress *object,
 	return result;
 }
 
+/*
+ * Record multiple dependencies from an ObjectAddresses array and lock the
+ * referenced objects, after first removing any duplicates.
+ */
+void
+lock_record_object_address_dependencies(const ObjectAddress *depender,
+										ObjectAddresses *referenced,
+										DependencyType behavior)
+{
+	eliminate_duplicate_dependencies(referenced);
+	LockNotPinnedObjectsById(referenced->refs, referenced->numrefs);
+	recordMultipleDependencies(depender,
+							   referenced->refs, referenced->numrefs,
+							   behavior);
+}
+
 /*
  * Record multiple dependencies from an ObjectAddresses array, after first
  * removing any duplicates.
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index a122bbffce..00977e56c4 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -843,6 +843,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId,
 						 tupdesc->attrs[i].atttypid);
+		LockNotPinnedObject(TypeRelationId, tupdesc->attrs[i].atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -851,6 +852,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 tupdesc->attrs[i].attcollation);
+			LockNotPinnedObject(CollationRelationId, tupdesc->attrs[i].attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1451,11 +1453,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1469,6 +1473,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3383,6 +3388,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3390,6 +3396,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index 55fdde4b24..dcd2158422 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1115,6 +1115,7 @@ index_create(Relation heapRelation,
 		else
 		{
 			bool		have_simple_col = false;
+			bool		locked_object = false;
 
 			addrs = new_object_addresses();
 
@@ -1127,6 +1128,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					if (!locked_object)
+					{
+						LockNotPinnedObject(RelationRelationId, heapRelationId);
+						locked_object = true;
+					}
 					have_simple_col = true;
 				}
 			}
@@ -1142,6 +1149,8 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				LockNotPinnedObject(RelationRelationId, heapRelationId);
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1157,9 +1166,13 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			LockNotPinnedObject(RelationRelationId, parentIndexRelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			LockNotPinnedObject(RelationRelationId, heapRelationId);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1175,6 +1188,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1183,6 +1197,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1987,6 +2002,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -1998,9 +2021,12 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(heapRelation));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..6d7abd3738 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949..a47e3c5507 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d..dcce454f00 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d51..d3707e424c 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f701229..78498b8c20 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 3baf9231ed..c4cdbd7c58 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -252,17 +252,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (constraintNTotalKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < constraintNTotalKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, relId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			LockNotPinnedObject(RelationRelationId, relId);
 		}
 	}
 
@@ -275,6 +284,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -294,17 +304,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (foreignNKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < foreignNKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, foreignRelId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			LockNotPinnedObject(RelationRelationId, foreignRelId);
 		}
 	}
 
@@ -320,6 +339,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		LockNotPinnedObject(RelationRelationId, indexRelId);
 	}
 
 	if (foreignNKeys > 0)
@@ -339,15 +359,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -858,9 +881,12 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac..25881654d6 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index cfd7ef51df..538b6c3c2c 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,21 +20,20 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
-
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
  * The first argument is the dependent object, the second the one it
@@ -100,6 +99,34 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		LOCKTAG		tag;
+
+		if (!isObjectPinned(referenced) && ObjectByIdExist(referenced))
+		{
+			if (referenced->classId != RelationRelationId)
+				SET_LOCKTAG_OBJECT(tag,
+								   MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId,
+								   0);
+			else
+			{
+				Assert(!IsSharedRelation(referenced->objectId));
+
+				SET_LOCKTAG_RELATION(tag, MyDatabaseId, referenced->objectId);
+			}
+		}
+
+		/*
+		 * Assert the referenced object is locked if it should be visible (see
+		 * the comment related to LockNotPinnedObject() in TypeCreate()) and
+		 * if not pinned.
+		 */
+		Assert(!ObjectByIdExist(referenced) || isObjectPinned(referenced) ||
+			   ObjectIsLocked(&tag));
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -239,6 +266,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -706,7 +734,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a..e8374eec88 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f..116e524390 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 0602398a54..b44a7f9d78 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -438,10 +438,13 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	LockNotPinnedObject(RelationRelationId, relid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -454,6 +457,8 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	for (int i = 0; i < natts; i++)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, attarray[i]);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -661,10 +666,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba410..e5b5a0b6f8 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed8..82ee7bc2e3 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,37 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid not added to pg_class yet (In heap_create_with_catalog(),
+		 * AddNewRelationType() is called before AddNewRelationTuple()).
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +543,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 738bc46ae8..a4d8342ca1 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -367,6 +367,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		LockNotPinnedObject(RelationRelationId, relOid);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb447..57e86f576a 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -807,6 +810,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc..8616a7c9fa 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 78f96789b0..fb95d17738 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1272,6 +1272,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1280,6 +1281,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1381,6 +1384,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r1);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1389,6 +1394,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r2);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index 7a5ed6b985..8d0cdec59e 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index 1643c8c69a..669a5d6dd8 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -1924,6 +1924,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -1932,6 +1933,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -2968,6 +2970,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3258,6 +3261,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3414,6 +3418,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1f..735bca486c 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 6593fd7d81..8207ef08b3 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1446,6 +1446,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1459,6 +1460,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1962,21 +1964,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 309389e20d..76849e558e 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4377,8 +4377,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			LockNotPinnedObject(RelationRelationId, parentOid);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			LockNotPinnedObject(RelationRelationId, partitionIdx->rd_index->indrelid);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5..e70afd216c 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 5872a3e192..58a69e7cc2 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba824..9da98cbeec 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017e..fadfd9064f 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index 28f8522264..7fbebf2052 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1681,6 +1681,8 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(tablerel));
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d2..9f0b03388a 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -88,6 +88,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	bool		build_mcv;
 	bool		build_expressions;
 	bool		requested_type = false;
+	bool		locked_object = false;
 	int			i;
 	ListCell   *cell;
 	ListCell   *cell2;
@@ -536,6 +537,12 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		if (!locked_object)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked_object = true;
+		}
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +560,8 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +582,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 66cda26a25..117259fba7 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3438,6 +3438,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, parentOid);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7349,7 +7350,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10174,6 +10177,7 @@ addFkRecurseReferenced(List **wqueue, Constraint *fkconstraint, Relation rel,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+		LockNotPinnedObject(ConstraintRelationId, parentConstr);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
 	}
 
@@ -10465,8 +10469,11 @@ addFkRecurseReferencing(List **wqueue, Constraint *fkconstraint, Relation rel,
 			 */
 			ObjectAddressSet(address, ConstraintRelationId, constrOid);
 			ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, partitionId);
+
+			LockNotPinnedObject(RelationRelationId, partitionId);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 			/* Make all this visible before recursing */
@@ -10967,9 +10974,12 @@ CloneFkReferencing(List **wqueue, Relation parentRel, Relation partRel)
 		/* Set up partition dependencies for the new constraint */
 		ObjectAddressSet(address, ConstraintRelationId, constrOid);
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrOid);
+		LockDatabaseObject(ConstraintRelationId, parentConstrOid, 0, AccessShareLock);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(partRel));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(partRel));
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 		/* Done with the cloned constraint's tuple */
@@ -13254,7 +13264,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -14816,6 +14828,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -14835,6 +14848,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -16434,6 +16448,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17192,14 +17207,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 		CatalogTupleUpdate(classRel, &classTup->t_self, classTup);
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
-								relOid,
-								NamespaceRelationId,
-								oldNspOid,
-								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
+									relOid,
+									NamespaceRelationId,
+									oldNspOid,
+									newNspOid) != 1)
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	if (!already_done)
 	{
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 58b7fc5bbd..4e60a3c06f 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1018,8 +1018,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1027,6 +1025,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1045,6 +1050,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1058,6 +1064,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1070,6 +1077,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1077,6 +1086,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			LockNotPinnedObject(RelationRelationId, constrrelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1091,6 +1102,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1100,8 +1112,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1110,12 +1125,19 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	if (columns != NULL)
 	{
 		int			i;
+		bool		locked_object = false;
 
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			if (!locked_object)
+			{
+				LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
+				locked_object = true;
+			}
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1255,9 +1277,12 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e..cba2b32a4d 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -66,12 +66,12 @@ static DefElem *buildDefItem(const char *name, const char *val,
 /* --------------------- TS Parser commands ------------------------ */
 
 /*
- * lookup a parser support function and return its OID (as a Datum)
+ * lookup a parser support function and return its OID
  *
  * attnum is the pg_ts_parser column the function will go into
  */
-static Datum
-get_ts_parser_func(DefElem *defel, int attnum)
+static Oid
+get_ts_parser_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[3];
@@ -125,7 +125,7 @@ get_ts_parser_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,38 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
-			values[Anum_pg_ts_parser_prsstart - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsstart);
+
+			values[Anum_pg_ts_parser_prsstart - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
-			values[Anum_pg_ts_parser_prstoken - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prstoken);
+
+			values[Anum_pg_ts_parser_prstoken - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
-			values[Anum_pg_ts_parser_prsend - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsend);
+
+			values[Anum_pg_ts_parser_prsend - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
-			values[Anum_pg_ts_parser_prsheadline - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsheadline);
+
+			values[Anum_pg_ts_parser_prsheadline - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
-			values[Anum_pg_ts_parser_prslextype - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prslextype);
+
+			values[Anum_pg_ts_parser_prslextype - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +485,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -601,12 +616,12 @@ AlterTSDictionary(AlterTSDictionaryStmt *stmt)
 /* ---------------------- TS Template commands -----------------------*/
 
 /*
- * lookup a template support function and return its OID (as a Datum)
+ * lookup a template support function and return its OID
  *
  * attnum is the pg_ts_template column the function will go into
  */
-static Datum
-get_ts_template_func(DefElem *defel, int attnum)
+static Oid
+get_ts_template_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[4];
@@ -642,7 +657,7 @@ get_ts_template_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -723,6 +738,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +749,19 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
-			values[Anum_pg_ts_template_tmplinit - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmplinit);
+
+			values[Anum_pg_ts_template_tmplinit - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
-			values[Anum_pg_ts_template_tmpllexize - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmpllexize);
+
+			values[Anum_pg_ts_template_tmpllexize - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -879,6 +899,7 @@ makeConfigurationDependencies(HeapTuple tuple, bool removeOld,
 			referenced.objectId = cfgmap->mapdict;
 			referenced.objectSubId = 0;
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 		}
 
 		systable_endscan(scan);
@@ -998,6 +1019,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1156,6 +1181,7 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
@@ -1168,7 +1194,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1210,10 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1445,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1489,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a1e713335..9febaa24a7 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2672,6 +2674,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4276,10 +4317,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4571,6 +4615,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4619,6 +4664,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bf..c930eca262 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, eventrel_oid);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1..60e8539fe3 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 6908ca7180..93da8b353e 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,9 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObjectsById(const ObjectAddress *object, int nobject);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -128,6 +131,9 @@ extern void add_exact_object_address(const ObjectAddress *object,
 extern bool object_address_present(const ObjectAddress *object,
 								   const ObjectAddresses *addrs);
 
+extern void lock_record_object_address_dependencies(const ObjectAddress *depender,
+													ObjectAddresses *referenced,
+													DependencyType behavior);
 extern void record_object_address_dependencies(const ObjectAddress *depender,
 											   ObjectAddresses *referenced,
 											   DependencyType behavior);
@@ -172,6 +178,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..56f746264b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/include/storage/lock.h b/src/include/storage/lock.h
index 0017d4b868..f7cbb224fc 100644
--- a/src/include/storage/lock.h
+++ b/src/include/storage/lock.h
@@ -568,6 +568,15 @@ extern void LockReleaseSession(LOCKMETHODID lockmethodid);
 extern void LockReleaseCurrentOwner(LOCALLOCK **locallocks, int nlocks);
 extern void LockReassignCurrentOwner(LOCALLOCK **locallocks, int nlocks);
 extern bool LockHeldByMe(const LOCKTAG *locktag, LOCKMODE lockmode);
+
+#define ObjectIsLocked(tag) \
+	LockHeldByMe(tag,ShareLock) || LockHeldByMe(tag,AccessExclusiveLock) || \
+	LockHeldByMe(tag,RowExclusiveLock) || LockHeldByMe(tag,RowShareLock) || \
+	LockHeldByMe(tag,AccessShareLock) || \
+	LockHeldByMe(tag,ShareRowExclusiveLock) || \
+	LockHeldByMe(tag,ExclusiveLock) || \
+	LockHeldByMe(tag,ShareUpdateExclusiveLock)
+
 #ifdef USE_ASSERT_CHECKING
 extern HTAB *GetLockMethodLocalHash(void);
 #endif
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 0342eb39e4..1b67f0bffe 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -114,3 +114,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/modules/test_oat_hooks/expected/alter_table.out b/src/test/modules/test_oat_hooks/expected/alter_table.out
index 8cbacca2c9..df8d276dfc 100644
--- a/src/test/modules/test_oat_hooks/expected/alter_table.out
+++ b/src/test/modules/test_oat_hooks/expected/alter_table.out
@@ -37,6 +37,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE RULE test_oat_notify AS
   ON UPDATE TO test_oat_schema.test_oat_tab
@@ -62,8 +64,6 @@ BEGIN
   END IF;
 END; $$;
 NOTICE:  in process utility: superuser attempting CREATE FUNCTION
-NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
-NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [explicit]
 NOTICE:  in object access: superuser finished create (subId=0x0) [explicit]
 NOTICE:  in process utility: superuser finished CREATE FUNCTION
diff --git a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
index effdc49145..da6d931994 100644
--- a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
+++ b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
@@ -86,6 +86,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE INDEX regress_test_table_t_idx ON regress_test_table (t);
 NOTICE:  in process utility: superuser attempting CREATE INDEX
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 673361e840..c2115ea601 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2867,11 +2867,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-07-01 09:39                                                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-02 05:56                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-07-01 09:39 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, Jun 26, 2024 at 10:24:41AM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Fri, Jun 21, 2024 at 01:22:43PM +0000, Bertrand Drouvot wrote:
> > Another thought for the RelationRelationId class case: we could check if there
> > is a lock first and if there is no lock then acquire one. That way that would
> > ensure the relation is always locked (so no "risk" anymore), but OTOH it may
> > add "unecessary" locking (see 2. mentioned previously).
> 
> Please find attached v12 implementing this idea for the RelationRelationId class
> case. As mentioned, it may add unnecessary locking for 2. but I think that's
> worth it to ensure that we are always on the safe side of thing. This idea is
> implemented in LockNotPinnedObjectById().

Please find attached v13, mandatory rebase due to 0cecc908e97. In passing, make
use of CheckRelationOidLockedByMe() added in 0cecc908e97.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v13-0001-Avoid-orphaned-objects-dependencies.patch (100.1K, ../../ZoJ5RVtMziIa3TQp@ip-10-97-1-34.eu-west-3.compute.internal/2-v13-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 461ae5d2fa037b2b9fd285c2a328c8bc785eaec8 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v13] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch takes into account any type of objects except the ones that are pinned
(they are not droppable because the system requires it).

A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that's worth it.

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 121 +++++++++++++++-
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  26 ++++
 src/backend/catalog/objectaddress.c           |  57 ++++++++
 src/backend/catalog/pg_aggregate.c            |   9 ++
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  26 ++++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  40 +++++-
 src/backend/catalog/pg_operator.c             |  19 +++
 src/backend/catalog/pg_proc.c                 |  17 ++-
 src/backend/catalog/pg_publication.c          |   7 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  39 ++++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   7 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 +++
 src/backend/commands/operatorcmds.c           |  30 ++++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   2 +
 src/backend/commands/statscmds.c              |  10 ++
 src/backend/commands/tablecmds.c              |  34 +++--
 src/backend/commands/trigger.c                |  29 +++-
 src/backend/commands/tsearchcmds.c            |  81 +++++++----
 src/backend/commands/typecmds.c               |  84 ++++++++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   7 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 .../test_oat_hooks/expected/alter_table.out   |   4 +-
 .../expected/test_oat_hooks.out               |   2 +
 src/test/regress/expected/alter_table.out     |  11 +-
 46 files changed, 903 insertions(+), 54 deletions(-)
  33.2% src/backend/catalog/
  35.0% src/backend/commands/
  17.3% src/test/isolation/expected/
  10.8% src/test/isolation/specs/
   3.4% src/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index a44ccee3b68..9a24872a303 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1413,6 +1413,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 0489cbabcb8..f002902d1e0 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,96 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description = NULL;
+
+	if (isObjectPinned(object))
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	if (object->classId == RelationRelationId)
+	{
+		Assert(!IsSharedRelation(object->objectId));
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+	}
+	else
+	{
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+void
+LockNotPinnedObjectsById(const ObjectAddress *object, int nobject)
+{
+	int			i;
+
+	if (nobject < 0)
+		return;
+
+	for (i = 0; i < nobject; i++, object++)
+		LockNotPinnedObjectById(object);
+
+	return;
+}
+
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1564,13 +1654,8 @@ recordDependencyOnExpr(const ObjectAddress *depender,
 	/* Scan the expression tree for referenceable objects */
 	find_expr_references_walker(expr, &context);
 
-	/* Remove any duplicates */
-	eliminate_duplicate_dependencies(context.addrs);
-
-	/* And record 'em */
-	recordMultipleDependencies(depender,
-							   context.addrs->refs, context.addrs->numrefs,
-							   behavior);
+	/* Record all of them (this includes duplicate elimination) */
+	lock_record_object_address_dependencies(depender, context.addrs, behavior);
 
 	free_object_addresses(context.addrs);
 }
@@ -1654,14 +1739,19 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 
 		/* Record the self-dependencies with the appropriate direction */
 		if (!reverse_self)
+		{
+			LockNotPinnedObjectsById(self_addrs->refs, self_addrs->numrefs);
 			recordMultipleDependencies(depender,
 									   self_addrs->refs, self_addrs->numrefs,
 									   self_behavior);
+		}
 		else
 		{
 			/* Can't use recordMultipleDependencies, so do it the hard way */
 			int			selfref;
 
+			LockNotPinnedObjectById(depender);
+
 			for (selfref = 0; selfref < self_addrs->numrefs; selfref++)
 			{
 				ObjectAddress *thisobj = self_addrs->refs + selfref;
@@ -1674,6 +1764,7 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 	}
 
 	/* Record the external dependencies */
+	LockNotPinnedObjectsById(context.addrs->refs, context.addrs->numrefs);
 	recordMultipleDependencies(depender,
 							   context.addrs->refs, context.addrs->numrefs,
 							   behavior);
@@ -2734,6 +2825,22 @@ stack_address_present_add_flags(const ObjectAddress *object,
 	return result;
 }
 
+/*
+ * Record multiple dependencies from an ObjectAddresses array and lock the
+ * referenced objects, after first removing any duplicates.
+ */
+void
+lock_record_object_address_dependencies(const ObjectAddress *depender,
+										ObjectAddresses *referenced,
+										DependencyType behavior)
+{
+	eliminate_duplicate_dependencies(referenced);
+	LockNotPinnedObjectsById(referenced->refs, referenced->numrefs);
+	recordMultipleDependencies(depender,
+							   referenced->refs, referenced->numrefs,
+							   behavior);
+}
+
 /*
  * Record multiple dependencies from an ObjectAddresses array, after first
  * removing any duplicates.
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index ae2efdc760d..4799331fe10 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -843,6 +843,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId,
 						 tupdesc->attrs[i].atttypid);
+		LockNotPinnedObject(TypeRelationId, tupdesc->attrs[i].atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -851,6 +852,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 tupdesc->attrs[i].attcollation);
+			LockNotPinnedObject(CollationRelationId, tupdesc->attrs[i].attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1458,11 +1460,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1476,6 +1480,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3390,6 +3395,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3397,6 +3403,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index a819b4197ce..d6d1abfcf5a 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1116,6 +1116,7 @@ index_create(Relation heapRelation,
 		else
 		{
 			bool		have_simple_col = false;
+			bool		locked_object = false;
 
 			addrs = new_object_addresses();
 
@@ -1128,6 +1129,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					if (!locked_object)
+					{
+						LockNotPinnedObject(RelationRelationId, heapRelationId);
+						locked_object = true;
+					}
 					have_simple_col = true;
 				}
 			}
@@ -1143,6 +1150,8 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				LockNotPinnedObject(RelationRelationId, heapRelationId);
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1158,9 +1167,13 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			LockNotPinnedObject(RelationRelationId, parentIndexRelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			LockNotPinnedObject(RelationRelationId, heapRelationId);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1176,6 +1189,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1184,6 +1198,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1988,6 +2003,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -1999,9 +2022,12 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(heapRelation));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fde..6d7abd37383 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949f..a47e3c55070 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d2..dcce454f000 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d514..d3707e424ca 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f7012299..78498b8c20d 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 3baf9231ed0..c4cdbd7c583 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -252,17 +252,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (constraintNTotalKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < constraintNTotalKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, relId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			LockNotPinnedObject(RelationRelationId, relId);
 		}
 	}
 
@@ -275,6 +284,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -294,17 +304,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (foreignNKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < foreignNKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, foreignRelId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			LockNotPinnedObject(RelationRelationId, foreignRelId);
 		}
 	}
 
@@ -320,6 +339,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		LockNotPinnedObject(RelationRelationId, indexRelId);
 	}
 
 	if (foreignNKeys > 0)
@@ -339,15 +359,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -858,9 +881,12 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac5..25881654d63 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index cfd7ef51dfa..ebca5a452b4 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,21 +20,21 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
-
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
  * The first argument is the dependent object, the second the one it
@@ -100,6 +100,37 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		if (!isObjectPinned(referenced))
+		{
+			if (referenced->classId != RelationRelationId)
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag,
+								   MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId,
+								   0);
+				/* assert the referenced object is locked */
+				Assert(LockHeldByMe(&tag, AccessShareLock, false));
+			}
+			else
+			{
+				Assert(!IsSharedRelation(referenced->objectId));
+
+				/*
+				 * Assert the referenced object is locked if it should be
+				 * visible (see the comment related to LockNotPinnedObject()
+				 * in TypeCreate()).
+				 */
+				Assert(!ObjectByIdExist(referenced) ||
+					   CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -239,6 +270,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -706,7 +738,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a2..e8374eec882 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f6..116e524390b 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 0602398a545..b44a7f9d78a 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -438,10 +438,13 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	LockNotPinnedObject(RelationRelationId, relid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -454,6 +457,8 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	for (int i = 0; i < natts; i++)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, attarray[i]);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -661,10 +666,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba4106..e5b5a0b6f82 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed88..82ee7bc2e30 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,37 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid not added to pg_class yet (In heap_create_with_catalog(),
+		 * AddNewRelationType() is called before AddNewRelationTuple()).
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +543,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 738bc46ae82..a4d8342ca1f 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -367,6 +367,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		LockNotPinnedObject(RelationRelationId, relOid);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb4470..57e86f576a4 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -807,6 +810,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc8..8616a7c9fab 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 78f96789b0e..fb95d177383 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1272,6 +1272,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1280,6 +1281,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1381,6 +1384,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r1);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1389,6 +1394,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r2);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index 7a5ed6b9850..8d0cdec59e0 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index 1643c8c69a0..669a5d6dd8b 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -1924,6 +1924,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -1932,6 +1933,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -2968,6 +2970,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3258,6 +3261,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3414,6 +3418,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1fa..735bca486c0 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 6593fd7d811..8207ef08b3e 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1446,6 +1446,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1459,6 +1460,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1962,21 +1964,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 2caab88aa58..e6ff8476e84 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4380,8 +4380,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			LockNotPinnedObject(RelationRelationId, parentOid);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			LockNotPinnedObject(RelationRelationId, partitionIdx->rd_index->indrelid);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5d..e70afd216c2 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 5872a3e1922..58a69e7cc25 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba8249..9da98cbeec4 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017ef..fadfd9064fd 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index b4ad19c0539..0dfabee88e4 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1688,6 +1688,8 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(tablerel));
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d22..9f0b03388a1 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -88,6 +88,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	bool		build_mcv;
 	bool		build_expressions;
 	bool		requested_type = false;
+	bool		locked_object = false;
 	int			i;
 	ListCell   *cell;
 	ListCell   *cell2;
@@ -536,6 +537,12 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		if (!locked_object)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked_object = true;
+		}
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +560,8 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +582,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 8fcb1883234..c21e65d86db 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3438,6 +3438,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, parentOid);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7361,7 +7362,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10186,6 +10189,7 @@ addFkRecurseReferenced(List **wqueue, Constraint *fkconstraint, Relation rel,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+		LockNotPinnedObject(ConstraintRelationId, parentConstr);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
 	}
 
@@ -10477,8 +10481,11 @@ addFkRecurseReferencing(List **wqueue, Constraint *fkconstraint, Relation rel,
 			 */
 			ObjectAddressSet(address, ConstraintRelationId, constrOid);
 			ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, partitionId);
+
+			LockNotPinnedObject(RelationRelationId, partitionId);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 			/* Make all this visible before recursing */
@@ -10979,9 +10986,12 @@ CloneFkReferencing(List **wqueue, Relation parentRel, Relation partRel)
 		/* Set up partition dependencies for the new constraint */
 		ObjectAddressSet(address, ConstraintRelationId, constrOid);
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrOid);
+		LockDatabaseObject(ConstraintRelationId, parentConstrOid, 0, AccessShareLock);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(partRel));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(partRel));
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 		/* Done with the cloned constraint's tuple */
@@ -13266,7 +13276,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -14828,6 +14840,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -14847,6 +14860,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -16446,6 +16460,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17204,14 +17219,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 		CatalogTupleUpdate(classRel, &classTup->t_self, classTup);
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
-								relOid,
-								NamespaceRelationId,
-								oldNspOid,
-								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
+									relOid,
+									NamespaceRelationId,
+									oldNspOid,
+									newNspOid) != 1)
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	if (!already_done)
 	{
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 58b7fc5bbd5..4e60a3c06f6 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1018,8 +1018,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1027,6 +1025,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1045,6 +1050,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1058,6 +1064,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1070,6 +1077,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1077,6 +1086,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			LockNotPinnedObject(RelationRelationId, constrrelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1091,6 +1102,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1100,8 +1112,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1110,12 +1125,19 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	if (columns != NULL)
 	{
 		int			i;
+		bool		locked_object = false;
 
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			if (!locked_object)
+			{
+				LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
+				locked_object = true;
+			}
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1255,9 +1277,12 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e0..cba2b32a4de 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -66,12 +66,12 @@ static DefElem *buildDefItem(const char *name, const char *val,
 /* --------------------- TS Parser commands ------------------------ */
 
 /*
- * lookup a parser support function and return its OID (as a Datum)
+ * lookup a parser support function and return its OID
  *
  * attnum is the pg_ts_parser column the function will go into
  */
-static Datum
-get_ts_parser_func(DefElem *defel, int attnum)
+static Oid
+get_ts_parser_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[3];
@@ -125,7 +125,7 @@ get_ts_parser_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,38 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
-			values[Anum_pg_ts_parser_prsstart - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsstart);
+
+			values[Anum_pg_ts_parser_prsstart - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
-			values[Anum_pg_ts_parser_prstoken - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prstoken);
+
+			values[Anum_pg_ts_parser_prstoken - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
-			values[Anum_pg_ts_parser_prsend - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsend);
+
+			values[Anum_pg_ts_parser_prsend - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
-			values[Anum_pg_ts_parser_prsheadline - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsheadline);
+
+			values[Anum_pg_ts_parser_prsheadline - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
-			values[Anum_pg_ts_parser_prslextype - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prslextype);
+
+			values[Anum_pg_ts_parser_prslextype - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +485,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -601,12 +616,12 @@ AlterTSDictionary(AlterTSDictionaryStmt *stmt)
 /* ---------------------- TS Template commands -----------------------*/
 
 /*
- * lookup a template support function and return its OID (as a Datum)
+ * lookup a template support function and return its OID
  *
  * attnum is the pg_ts_template column the function will go into
  */
-static Datum
-get_ts_template_func(DefElem *defel, int attnum)
+static Oid
+get_ts_template_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[4];
@@ -642,7 +657,7 @@ get_ts_template_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -723,6 +738,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +749,19 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
-			values[Anum_pg_ts_template_tmplinit - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmplinit);
+
+			values[Anum_pg_ts_template_tmplinit - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
-			values[Anum_pg_ts_template_tmpllexize - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmpllexize);
+
+			values[Anum_pg_ts_template_tmpllexize - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -879,6 +899,7 @@ makeConfigurationDependencies(HeapTuple tuple, bool removeOld,
 			referenced.objectId = cfgmap->mapdict;
 			referenced.objectSubId = 0;
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 		}
 
 		systable_endscan(scan);
@@ -998,6 +1019,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1156,6 +1181,7 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
@@ -1168,7 +1194,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1210,10 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1445,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1489,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a1e7133356..9febaa24a75 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2672,6 +2674,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4276,10 +4317,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4571,6 +4615,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4619,6 +4664,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bfe..c930eca2624 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, eventrel_oid);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1c..60e8539fe3f 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 6908ca7180a..93da8b353ea 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,9 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObjectsById(const ObjectAddress *object, int nobject);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -128,6 +131,9 @@ extern void add_exact_object_address(const ObjectAddress *object,
 extern bool object_address_present(const ObjectAddress *object,
 								   const ObjectAddresses *addrs);
 
+extern void lock_record_object_address_dependencies(const ObjectAddress *depender,
+													ObjectAddresses *referenced,
+													DependencyType behavior);
 extern void record_object_address_dependencies(const ObjectAddress *depender,
 											   ObjectAddresses *referenced,
 											   DependencyType behavior);
@@ -172,6 +178,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e320..56f746264b0 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 00000000000..9b645d7aa55
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 6da98cffaca..ef6a7075bcb 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -117,3 +117,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 00000000000..5d04dfe9dc6
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/modules/test_oat_hooks/expected/alter_table.out b/src/test/modules/test_oat_hooks/expected/alter_table.out
index 8cbacca2c9b..df8d276dfcc 100644
--- a/src/test/modules/test_oat_hooks/expected/alter_table.out
+++ b/src/test/modules/test_oat_hooks/expected/alter_table.out
@@ -37,6 +37,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE RULE test_oat_notify AS
   ON UPDATE TO test_oat_schema.test_oat_tab
@@ -62,8 +64,6 @@ BEGIN
   END IF;
 END; $$;
 NOTICE:  in process utility: superuser attempting CREATE FUNCTION
-NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
-NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [explicit]
 NOTICE:  in object access: superuser finished create (subId=0x0) [explicit]
 NOTICE:  in process utility: superuser finished CREATE FUNCTION
diff --git a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
index effdc491458..da6d931994d 100644
--- a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
+++ b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
@@ -86,6 +86,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE INDEX regress_test_table_t_idx ON regress_test_table (t);
 NOTICE:  in process utility: superuser attempting CREATE INDEX
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 673361e8404..c2115ea6013 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2867,11 +2867,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-01 09:39                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-07-02 05:56                                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-10 07:31                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-07-02 05:56 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Mon, Jul 01, 2024 at 09:39:17AM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Wed, Jun 26, 2024 at 10:24:41AM +0000, Bertrand Drouvot wrote:
> > Hi,
> > 
> > On Fri, Jun 21, 2024 at 01:22:43PM +0000, Bertrand Drouvot wrote:
> > > Another thought for the RelationRelationId class case: we could check if there
> > > is a lock first and if there is no lock then acquire one. That way that would
> > > ensure the relation is always locked (so no "risk" anymore), but OTOH it may
> > > add "unecessary" locking (see 2. mentioned previously).
> > 
> > Please find attached v12 implementing this idea for the RelationRelationId class
> > case. As mentioned, it may add unnecessary locking for 2. but I think that's
> > worth it to ensure that we are always on the safe side of thing. This idea is
> > implemented in LockNotPinnedObjectById().
> 
> Please find attached v13, mandatory rebase due to 0cecc908e97. In passing, make
> use of CheckRelationOidLockedByMe() added in 0cecc908e97.

Please find attached v14, mandatory rebase due to 65b71dec2d5.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v14-0001-Avoid-orphaned-objects-dependencies.patch (100.1K, ../../ZoOWh65dEXamDYDW@ip-10-97-1-34.eu-west-3.compute.internal/2-v14-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 31767e9eb290909943d03408d9f8e827cf17e0bd Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v14] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch takes into account any type of objects except the ones that are pinned
(they are not droppable because the system requires it).

A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that's worth it.

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 121 +++++++++++++++-
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  26 ++++
 src/backend/catalog/objectaddress.c           |  57 ++++++++
 src/backend/catalog/pg_aggregate.c            |   9 ++
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  26 ++++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  40 +++++-
 src/backend/catalog/pg_operator.c             |  19 +++
 src/backend/catalog/pg_proc.c                 |  17 ++-
 src/backend/catalog/pg_publication.c          |   7 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  39 ++++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   7 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 +++
 src/backend/commands/operatorcmds.c           |  30 ++++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   2 +
 src/backend/commands/statscmds.c              |  10 ++
 src/backend/commands/tablecmds.c              |  34 +++--
 src/backend/commands/trigger.c                |  29 +++-
 src/backend/commands/tsearchcmds.c            |  81 +++++++----
 src/backend/commands/typecmds.c               |  84 ++++++++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   7 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 .../test_oat_hooks/expected/alter_table.out   |   4 +-
 .../expected/test_oat_hooks.out               |   2 +
 src/test/regress/expected/alter_table.out     |  11 +-
 46 files changed, 903 insertions(+), 54 deletions(-)
  33.2% src/backend/catalog/
  35.0% src/backend/commands/
  17.3% src/test/isolation/expected/
  10.8% src/test/isolation/specs/
   3.4% src/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index a44ccee3b68..9a24872a303 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1413,6 +1413,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 0489cbabcb8..f002902d1e0 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,96 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description = NULL;
+
+	if (isObjectPinned(object))
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	if (object->classId == RelationRelationId)
+	{
+		Assert(!IsSharedRelation(object->objectId));
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+	}
+	else
+	{
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+void
+LockNotPinnedObjectsById(const ObjectAddress *object, int nobject)
+{
+	int			i;
+
+	if (nobject < 0)
+		return;
+
+	for (i = 0; i < nobject; i++, object++)
+		LockNotPinnedObjectById(object);
+
+	return;
+}
+
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1564,13 +1654,8 @@ recordDependencyOnExpr(const ObjectAddress *depender,
 	/* Scan the expression tree for referenceable objects */
 	find_expr_references_walker(expr, &context);
 
-	/* Remove any duplicates */
-	eliminate_duplicate_dependencies(context.addrs);
-
-	/* And record 'em */
-	recordMultipleDependencies(depender,
-							   context.addrs->refs, context.addrs->numrefs,
-							   behavior);
+	/* Record all of them (this includes duplicate elimination) */
+	lock_record_object_address_dependencies(depender, context.addrs, behavior);
 
 	free_object_addresses(context.addrs);
 }
@@ -1654,14 +1739,19 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 
 		/* Record the self-dependencies with the appropriate direction */
 		if (!reverse_self)
+		{
+			LockNotPinnedObjectsById(self_addrs->refs, self_addrs->numrefs);
 			recordMultipleDependencies(depender,
 									   self_addrs->refs, self_addrs->numrefs,
 									   self_behavior);
+		}
 		else
 		{
 			/* Can't use recordMultipleDependencies, so do it the hard way */
 			int			selfref;
 
+			LockNotPinnedObjectById(depender);
+
 			for (selfref = 0; selfref < self_addrs->numrefs; selfref++)
 			{
 				ObjectAddress *thisobj = self_addrs->refs + selfref;
@@ -1674,6 +1764,7 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 	}
 
 	/* Record the external dependencies */
+	LockNotPinnedObjectsById(context.addrs->refs, context.addrs->numrefs);
 	recordMultipleDependencies(depender,
 							   context.addrs->refs, context.addrs->numrefs,
 							   behavior);
@@ -2734,6 +2825,22 @@ stack_address_present_add_flags(const ObjectAddress *object,
 	return result;
 }
 
+/*
+ * Record multiple dependencies from an ObjectAddresses array and lock the
+ * referenced objects, after first removing any duplicates.
+ */
+void
+lock_record_object_address_dependencies(const ObjectAddress *depender,
+										ObjectAddresses *referenced,
+										DependencyType behavior)
+{
+	eliminate_duplicate_dependencies(referenced);
+	LockNotPinnedObjectsById(referenced->refs, referenced->numrefs);
+	recordMultipleDependencies(depender,
+							   referenced->refs, referenced->numrefs,
+							   behavior);
+}
+
 /*
  * Record multiple dependencies from an ObjectAddresses array, after first
  * removing any duplicates.
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index 00074c8a948..1266101d906 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -844,6 +844,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		/* Add dependency info */
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId, attr->atttypid);
+		LockNotPinnedObject(TypeRelationId, attr->atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -852,6 +853,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 attr->attcollation);
+			LockNotPinnedObject(CollationRelationId, attr->attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1459,11 +1461,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1477,6 +1481,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3391,6 +3396,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3398,6 +3404,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index a819b4197ce..d6d1abfcf5a 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1116,6 +1116,7 @@ index_create(Relation heapRelation,
 		else
 		{
 			bool		have_simple_col = false;
+			bool		locked_object = false;
 
 			addrs = new_object_addresses();
 
@@ -1128,6 +1129,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					if (!locked_object)
+					{
+						LockNotPinnedObject(RelationRelationId, heapRelationId);
+						locked_object = true;
+					}
 					have_simple_col = true;
 				}
 			}
@@ -1143,6 +1150,8 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				LockNotPinnedObject(RelationRelationId, heapRelationId);
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1158,9 +1167,13 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			LockNotPinnedObject(RelationRelationId, parentIndexRelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			LockNotPinnedObject(RelationRelationId, heapRelationId);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1176,6 +1189,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1184,6 +1198,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1988,6 +2003,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -1999,9 +2022,12 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(heapRelation));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fde..6d7abd37383 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949f..a47e3c55070 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d2..dcce454f000 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d514..d3707e424ca 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f7012299..78498b8c20d 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 3baf9231ed0..c4cdbd7c583 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -252,17 +252,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (constraintNTotalKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < constraintNTotalKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, relId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			LockNotPinnedObject(RelationRelationId, relId);
 		}
 	}
 
@@ -275,6 +284,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -294,17 +304,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (foreignNKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < foreignNKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, foreignRelId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			LockNotPinnedObject(RelationRelationId, foreignRelId);
 		}
 	}
 
@@ -320,6 +339,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		LockNotPinnedObject(RelationRelationId, indexRelId);
 	}
 
 	if (foreignNKeys > 0)
@@ -339,15 +359,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -858,9 +881,12 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac5..25881654d63 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index cfd7ef51dfa..ebca5a452b4 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,21 +20,21 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
-
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
  * The first argument is the dependent object, the second the one it
@@ -100,6 +100,37 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		if (!isObjectPinned(referenced))
+		{
+			if (referenced->classId != RelationRelationId)
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag,
+								   MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId,
+								   0);
+				/* assert the referenced object is locked */
+				Assert(LockHeldByMe(&tag, AccessShareLock, false));
+			}
+			else
+			{
+				Assert(!IsSharedRelation(referenced->objectId));
+
+				/*
+				 * Assert the referenced object is locked if it should be
+				 * visible (see the comment related to LockNotPinnedObject()
+				 * in TypeCreate()).
+				 */
+				Assert(!ObjectByIdExist(referenced) ||
+					   CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -239,6 +270,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -706,7 +738,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a2..e8374eec882 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f6..116e524390b 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 0602398a545..b44a7f9d78a 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -438,10 +438,13 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	LockNotPinnedObject(RelationRelationId, relid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -454,6 +457,8 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	for (int i = 0; i < natts; i++)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, attarray[i]);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -661,10 +666,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba4106..e5b5a0b6f82 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed88..82ee7bc2e30 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,37 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid not added to pg_class yet (In heap_create_with_catalog(),
+		 * AddNewRelationType() is called before AddNewRelationTuple()).
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +543,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 738bc46ae82..a4d8342ca1f 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -367,6 +367,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		LockNotPinnedObject(RelationRelationId, relOid);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb4470..57e86f576a4 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -807,6 +810,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc8..8616a7c9fab 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 78f96789b0e..fb95d177383 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1272,6 +1272,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1280,6 +1281,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1381,6 +1384,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r1);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1389,6 +1394,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r2);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index 7a5ed6b9850..8d0cdec59e0 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index 1643c8c69a0..669a5d6dd8b 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -1924,6 +1924,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -1932,6 +1933,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -2968,6 +2970,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3258,6 +3261,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3414,6 +3418,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1fa..735bca486c0 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 6593fd7d811..8207ef08b3e 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1446,6 +1446,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1459,6 +1460,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1962,21 +1964,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 2caab88aa58..e6ff8476e84 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4380,8 +4380,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			LockNotPinnedObject(RelationRelationId, parentOid);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			LockNotPinnedObject(RelationRelationId, partitionIdx->rd_index->indrelid);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5d..e70afd216c2 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 5872a3e1922..58a69e7cc25 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba8249..9da98cbeec4 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017ef..fadfd9064fd 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index 9f28d40466b..c0634d0af90 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1688,6 +1688,8 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(tablerel));
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d22..9f0b03388a1 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -88,6 +88,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	bool		build_mcv;
 	bool		build_expressions;
 	bool		requested_type = false;
+	bool		locked_object = false;
 	int			i;
 	ListCell   *cell;
 	ListCell   *cell2;
@@ -536,6 +537,12 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		if (!locked_object)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked_object = true;
+		}
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +560,8 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +582,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 9e9dc5c2c13..155e9ec57df 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3419,6 +3419,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, parentOid);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7342,7 +7343,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10167,6 +10170,7 @@ addFkRecurseReferenced(List **wqueue, Constraint *fkconstraint, Relation rel,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+		LockNotPinnedObject(ConstraintRelationId, parentConstr);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
 	}
 
@@ -10458,8 +10462,11 @@ addFkRecurseReferencing(List **wqueue, Constraint *fkconstraint, Relation rel,
 			 */
 			ObjectAddressSet(address, ConstraintRelationId, constrOid);
 			ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, partitionId);
+
+			LockNotPinnedObject(RelationRelationId, partitionId);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 			/* Make all this visible before recursing */
@@ -10960,9 +10967,12 @@ CloneFkReferencing(List **wqueue, Relation parentRel, Relation partRel)
 		/* Set up partition dependencies for the new constraint */
 		ObjectAddressSet(address, ConstraintRelationId, constrOid);
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrOid);
+		LockDatabaseObject(ConstraintRelationId, parentConstrOid, 0, AccessShareLock);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(partRel));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(partRel));
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 		/* Done with the cloned constraint's tuple */
@@ -13247,7 +13257,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -14809,6 +14821,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -14828,6 +14841,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -16427,6 +16441,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17185,14 +17200,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 		CatalogTupleUpdate(classRel, &classTup->t_self, classTup);
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
-								relOid,
-								NamespaceRelationId,
-								oldNspOid,
-								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
+									relOid,
+									NamespaceRelationId,
+									oldNspOid,
+									newNspOid) != 1)
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	if (!already_done)
 	{
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 58b7fc5bbd5..4e60a3c06f6 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1018,8 +1018,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1027,6 +1025,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1045,6 +1050,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1058,6 +1064,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1070,6 +1077,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1077,6 +1086,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			LockNotPinnedObject(RelationRelationId, constrrelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1091,6 +1102,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1100,8 +1112,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1110,12 +1125,19 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	if (columns != NULL)
 	{
 		int			i;
+		bool		locked_object = false;
 
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			if (!locked_object)
+			{
+				LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
+				locked_object = true;
+			}
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1255,9 +1277,12 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e0..cba2b32a4de 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -66,12 +66,12 @@ static DefElem *buildDefItem(const char *name, const char *val,
 /* --------------------- TS Parser commands ------------------------ */
 
 /*
- * lookup a parser support function and return its OID (as a Datum)
+ * lookup a parser support function and return its OID
  *
  * attnum is the pg_ts_parser column the function will go into
  */
-static Datum
-get_ts_parser_func(DefElem *defel, int attnum)
+static Oid
+get_ts_parser_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[3];
@@ -125,7 +125,7 @@ get_ts_parser_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,38 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
-			values[Anum_pg_ts_parser_prsstart - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsstart);
+
+			values[Anum_pg_ts_parser_prsstart - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
-			values[Anum_pg_ts_parser_prstoken - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prstoken);
+
+			values[Anum_pg_ts_parser_prstoken - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
-			values[Anum_pg_ts_parser_prsend - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsend);
+
+			values[Anum_pg_ts_parser_prsend - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
-			values[Anum_pg_ts_parser_prsheadline - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsheadline);
+
+			values[Anum_pg_ts_parser_prsheadline - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
-			values[Anum_pg_ts_parser_prslextype - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prslextype);
+
+			values[Anum_pg_ts_parser_prslextype - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +485,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -601,12 +616,12 @@ AlterTSDictionary(AlterTSDictionaryStmt *stmt)
 /* ---------------------- TS Template commands -----------------------*/
 
 /*
- * lookup a template support function and return its OID (as a Datum)
+ * lookup a template support function and return its OID
  *
  * attnum is the pg_ts_template column the function will go into
  */
-static Datum
-get_ts_template_func(DefElem *defel, int attnum)
+static Oid
+get_ts_template_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[4];
@@ -642,7 +657,7 @@ get_ts_template_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -723,6 +738,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +749,19 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
-			values[Anum_pg_ts_template_tmplinit - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmplinit);
+
+			values[Anum_pg_ts_template_tmplinit - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
-			values[Anum_pg_ts_template_tmpllexize - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmpllexize);
+
+			values[Anum_pg_ts_template_tmpllexize - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -879,6 +899,7 @@ makeConfigurationDependencies(HeapTuple tuple, bool removeOld,
 			referenced.objectId = cfgmap->mapdict;
 			referenced.objectSubId = 0;
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 		}
 
 		systable_endscan(scan);
@@ -998,6 +1019,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1156,6 +1181,7 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
@@ -1168,7 +1194,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1210,10 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1445,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1489,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a1e7133356..9febaa24a75 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2672,6 +2674,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4276,10 +4317,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4571,6 +4615,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4619,6 +4664,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bfe..c930eca2624 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, eventrel_oid);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1c..60e8539fe3f 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 6908ca7180a..93da8b353ea 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,9 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObjectsById(const ObjectAddress *object, int nobject);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -128,6 +131,9 @@ extern void add_exact_object_address(const ObjectAddress *object,
 extern bool object_address_present(const ObjectAddress *object,
 								   const ObjectAddresses *addrs);
 
+extern void lock_record_object_address_dependencies(const ObjectAddress *depender,
+													ObjectAddresses *referenced,
+													DependencyType behavior);
 extern void record_object_address_dependencies(const ObjectAddress *depender,
 											   ObjectAddresses *referenced,
 											   DependencyType behavior);
@@ -172,6 +178,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e320..56f746264b0 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 00000000000..9b645d7aa55
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 6da98cffaca..ef6a7075bcb 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -117,3 +117,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 00000000000..5d04dfe9dc6
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/modules/test_oat_hooks/expected/alter_table.out b/src/test/modules/test_oat_hooks/expected/alter_table.out
index 8cbacca2c9b..df8d276dfcc 100644
--- a/src/test/modules/test_oat_hooks/expected/alter_table.out
+++ b/src/test/modules/test_oat_hooks/expected/alter_table.out
@@ -37,6 +37,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE RULE test_oat_notify AS
   ON UPDATE TO test_oat_schema.test_oat_tab
@@ -62,8 +64,6 @@ BEGIN
   END IF;
 END; $$;
 NOTICE:  in process utility: superuser attempting CREATE FUNCTION
-NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
-NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [explicit]
 NOTICE:  in object access: superuser finished create (subId=0x0) [explicit]
 NOTICE:  in process utility: superuser finished CREATE FUNCTION
diff --git a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
index effdc491458..da6d931994d 100644
--- a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
+++ b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
@@ -86,6 +86,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE INDEX regress_test_table_t_idx ON regress_test_table (t);
 NOTICE:  in process utility: superuser attempting CREATE INDEX
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 673361e8404..c2115ea6013 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2867,11 +2867,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-01 09:39                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-02 05:56                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-07-10 07:31                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-08-19 15:35                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-07-10 07:31 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Tue, Jul 02, 2024 at 05:56:23AM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Mon, Jul 01, 2024 at 09:39:17AM +0000, Bertrand Drouvot wrote:
> > Hi,
> > 
> > On Wed, Jun 26, 2024 at 10:24:41AM +0000, Bertrand Drouvot wrote:
> > > Hi,
> > > 
> > > On Fri, Jun 21, 2024 at 01:22:43PM +0000, Bertrand Drouvot wrote:
> > > > Another thought for the RelationRelationId class case: we could check if there
> > > > is a lock first and if there is no lock then acquire one. That way that would
> > > > ensure the relation is always locked (so no "risk" anymore), but OTOH it may
> > > > add "unecessary" locking (see 2. mentioned previously).
> > > 
> > > Please find attached v12 implementing this idea for the RelationRelationId class
> > > case. As mentioned, it may add unnecessary locking for 2. but I think that's
> > > worth it to ensure that we are always on the safe side of thing. This idea is
> > > implemented in LockNotPinnedObjectById().
> > 
> > Please find attached v13, mandatory rebase due to 0cecc908e97. In passing, make
> > use of CheckRelationOidLockedByMe() added in 0cecc908e97.
> 
> Please find attached v14, mandatory rebase due to 65b71dec2d5.

In [1] I mentioned that the object locking logic has been put outside of the 
dependency code except for:

recordDependencyOnExpr() 
recordDependencyOnSingleRelExpr()
makeConfigurationDependencies()

Please find attached v15 that also removes the logic outside of the 3 above 
functions. Well, for recordDependencyOnExpr() and recordDependencyOnSingleRelExpr()
that's now done in find_expr_references_walker(): It's somehow still in the
dependency code but at least it is now clear which objects we are locking (and
I'm not sure how we could do better than that for those 2 functions).

There is still one locking call in recordDependencyOnCurrentExtension() but I
think this one is clear enough and does not need to be put outside (for
the same reason mentioned in [1]).

So, to sum up:

A. Locking is now done exclusively with LockNotPinnedObject(Oid classid, Oid objid)
so that it's now always clear what object we want to acquire a lock for. It means
we are not manipulating directly an object address or a list of objects address
as it was the case when the locking was done "directly" within the dependency code.

B. A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

 1. The relation is already locked (could be an existing relation or a relation
 that we are creating).

 2. The relation is protected indirectly (i.e an index protected by a lock on
 its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that seems worth it. 

[1]: https://www.postgresql.org/message-id/ZnAVEBhlGvpDDVOD%40ip-10-97-1-34.eu-west-3.compute.internal

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v15-0001-Avoid-orphaned-objects-dependencies.patch (113.3K, ../../Zo44ut9e6R51OffX@ip-10-97-1-34.eu-west-3.compute.internal/2-v15-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From bc47856d85e9e4f61fc22bc29ec40419e957b7e6 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v15] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch takes into account any type of objects except the ones that are pinned
(they are not droppable because the system requires it).

A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that's worth it.

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 212 ++++++++++++++++++
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  26 +++
 src/backend/catalog/objectaddress.c           |  57 +++++
 src/backend/catalog/pg_aggregate.c            |   9 +
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  26 +++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  40 +++-
 src/backend/catalog/pg_operator.c             |  19 ++
 src/backend/catalog/pg_proc.c                 |  17 +-
 src/backend/catalog/pg_publication.c          |   7 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  39 ++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   7 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 ++
 src/backend/commands/operatorcmds.c           |  30 +++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   2 +
 src/backend/commands/statscmds.c              |  10 +
 src/backend/commands/tablecmds.c              |  34 ++-
 src/backend/commands/trigger.c                |  29 ++-
 src/backend/commands/tsearchcmds.c            |  73 +++++-
 src/backend/commands/typecmds.c               |  84 +++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   3 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 +++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++
 .../test_oat_hooks/expected/alter_table.out   |   4 +-
 .../expected/test_oat_hooks.out               |   2 +
 src/test/regress/expected/alter_table.out     |  11 +-
 46 files changed, 1011 insertions(+), 25 deletions(-)
  39.6% src/backend/catalog/
  30.5% src/backend/commands/
  16.7% src/test/isolation/expected/
  10.4% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index a44ccee3b6..9a24872a30 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1413,6 +1413,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 0489cbabcb..a3770d7206 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,81 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description = NULL;
+
+	if (isObjectPinned(object))
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	if (object->classId == RelationRelationId)
+	{
+		Assert(!IsSharedRelation(object->objectId));
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+	}
+	else
+	{
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1730,6 +1805,7 @@ find_expr_references_walker(Node *node,
 		if (rte->rtekind == RTE_RELATION)
 		{
 			/* If it's a plain relation, reference this column */
+			LockNotPinnedObject(RelationRelationId, rte->relid);
 			add_object_address(RelationRelationId, rte->relid, var->varattno,
 							   context->addrs);
 		}
@@ -1756,6 +1832,7 @@ find_expr_references_walker(Node *node,
 		Oid			objoid;
 
 		/* A constant must depend on the constant's datatype */
+		LockNotPinnedObject(TypeRelationId, con->consttype);
 		add_object_address(TypeRelationId, con->consttype, 0,
 						   context->addrs);
 
@@ -1767,8 +1844,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (OidIsValid(con->constcollid) &&
 			con->constcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, con->constcollid);
 			add_object_address(CollationRelationId, con->constcollid, 0,
 							   context->addrs);
+		}
 
 		/*
 		 * If it's a regclass or similar literal referring to an existing
@@ -1785,59 +1865,83 @@ find_expr_references_walker(Node *node,
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(PROCOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(ProcedureRelationId, objoid);
 						add_object_address(ProcedureRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGOPEROID:
 				case REGOPERATOROID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(OPEROID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(OperatorRelationId, objoid);
 						add_object_address(OperatorRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCLASSOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(RELOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(RelationRelationId, objoid);
 						add_object_address(RelationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGTYPEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TYPEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TypeRelationId, objoid);
 						add_object_address(TypeRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCOLLATIONOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(COLLOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(CollationRelationId, objoid);
 						add_object_address(CollationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCONFIGOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSCONFIGOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSConfigRelationId, objoid);
 						add_object_address(TSConfigRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGDICTIONARYOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSDICTOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSDictionaryRelationId, objoid);
 						add_object_address(TSDictionaryRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 				case REGNAMESPACEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(NAMESPACEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(NamespaceRelationId, objoid);
 						add_object_address(NamespaceRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 					/*
@@ -1859,18 +1963,23 @@ find_expr_references_walker(Node *node,
 		Param	   *param = (Param *) node;
 
 		/* A parameter must depend on the parameter's datatype */
+		LockNotPinnedObject(TypeRelationId, param->paramtype);
 		add_object_address(TypeRelationId, param->paramtype, 0,
 						   context->addrs);
 		/* and its collation, just as for Consts */
 		if (OidIsValid(param->paramcollid) &&
 			param->paramcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, param->paramcollid);
 			add_object_address(CollationRelationId, param->paramcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FuncExpr))
 	{
 		FuncExpr   *funcexpr = (FuncExpr *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, funcexpr->funcid);
 		add_object_address(ProcedureRelationId, funcexpr->funcid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1879,6 +1988,7 @@ find_expr_references_walker(Node *node,
 	{
 		OpExpr	   *opexpr = (OpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1887,6 +1997,7 @@ find_expr_references_walker(Node *node,
 	{
 		DistinctExpr *distinctexpr = (DistinctExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, distinctexpr->opno);
 		add_object_address(OperatorRelationId, distinctexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1895,6 +2006,7 @@ find_expr_references_walker(Node *node,
 	{
 		NullIfExpr *nullifexpr = (NullIfExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, nullifexpr->opno);
 		add_object_address(OperatorRelationId, nullifexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1903,6 +2015,7 @@ find_expr_references_walker(Node *node,
 	{
 		ScalarArrayOpExpr *opexpr = (ScalarArrayOpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1911,6 +2024,7 @@ find_expr_references_walker(Node *node,
 	{
 		Aggref	   *aggref = (Aggref *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, aggref->aggfnoid);
 		add_object_address(ProcedureRelationId, aggref->aggfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1919,6 +2033,7 @@ find_expr_references_walker(Node *node,
 	{
 		WindowFunc *wfunc = (WindowFunc *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, wfunc->winfnoid);
 		add_object_address(ProcedureRelationId, wfunc->winfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1935,8 +2050,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (sbsref->refrestype != sbsref->refcontainertype &&
 			sbsref->refrestype != sbsref->refelemtype)
+		{
+			LockNotPinnedObject(TypeRelationId, sbsref->refrestype);
 			add_object_address(TypeRelationId, sbsref->refrestype, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SubPlan))
@@ -1960,16 +2078,25 @@ find_expr_references_walker(Node *node,
 		 * anywhere else in the expression.
 		 */
 		if (OidIsValid(reltype))
+		{
+			LockNotPinnedObject(RelationRelationId, reltype);
 			add_object_address(RelationRelationId, reltype, fselect->fieldnum,
 							   context->addrs);
+		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fselect->resulttype);
 			add_object_address(TypeRelationId, fselect->resulttype, 0,
 							   context->addrs);
+		}
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(fselect->resultcollid) &&
 			fselect->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, fselect->resultcollid);
 			add_object_address(CollationRelationId, fselect->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FieldStore))
 	{
@@ -1980,53 +2107,76 @@ find_expr_references_walker(Node *node,
 		if (OidIsValid(reltype))
 		{
 			ListCell   *l;
+			bool	locked = false;
 
 			foreach(l, fstore->fieldnums)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
+					locked = true;
+				}
 				add_object_address(RelationRelationId, reltype, lfirst_int(l),
 								   context->addrs);
+			}
 		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fstore->resulttype);
 			add_object_address(TypeRelationId, fstore->resulttype, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, RelabelType))
 	{
 		RelabelType *relab = (RelabelType *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, relab->resulttype);
 		add_object_address(TypeRelationId, relab->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(relab->resultcollid) &&
 			relab->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, relab->resultcollid);
 			add_object_address(CollationRelationId, relab->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, CoerceViaIO))
 	{
 		CoerceViaIO *iocoerce = (CoerceViaIO *) node;
 
 		/* since there is no exposed function, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, iocoerce->resulttype);
 		add_object_address(TypeRelationId, iocoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(iocoerce->resultcollid) &&
 			iocoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, iocoerce->resultcollid);
 			add_object_address(CollationRelationId, iocoerce->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, ArrayCoerceExpr))
 	{
 		ArrayCoerceExpr *acoerce = (ArrayCoerceExpr *) node;
 
 		/* as above, depend on type */
+		LockNotPinnedObject(TypeRelationId, acoerce->resulttype);
 		add_object_address(TypeRelationId, acoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(acoerce->resultcollid) &&
 			acoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, acoerce->resultcollid);
 			add_object_address(CollationRelationId, acoerce->resultcollid, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, ConvertRowtypeExpr))
@@ -2034,6 +2184,7 @@ find_expr_references_walker(Node *node,
 		ConvertRowtypeExpr *cvt = (ConvertRowtypeExpr *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, cvt->resulttype);
 		add_object_address(TypeRelationId, cvt->resulttype, 0,
 						   context->addrs);
 	}
@@ -2041,6 +2192,7 @@ find_expr_references_walker(Node *node,
 	{
 		CollateExpr *coll = (CollateExpr *) node;
 
+		LockNotPinnedObject(CollationRelationId, coll->collOid);
 		add_object_address(CollationRelationId, coll->collOid, 0,
 						   context->addrs);
 	}
@@ -2048,6 +2200,7 @@ find_expr_references_walker(Node *node,
 	{
 		RowExpr    *rowexpr = (RowExpr *) node;
 
+		LockNotPinnedObject(TypeRelationId, rowexpr->row_typeid);
 		add_object_address(TypeRelationId, rowexpr->row_typeid, 0,
 						   context->addrs);
 	}
@@ -2058,11 +2211,13 @@ find_expr_references_walker(Node *node,
 
 		foreach(l, rcexpr->opnos)
 		{
+			LockNotPinnedObject(OperatorRelationId, lfirst_oid(l));
 			add_object_address(OperatorRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
 		foreach(l, rcexpr->opfamilies)
 		{
+			LockNotPinnedObject(OperatorFamilyRelationId, lfirst_oid(l));
 			add_object_address(OperatorFamilyRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
@@ -2072,6 +2227,7 @@ find_expr_references_walker(Node *node,
 	{
 		CoerceToDomain *cd = (CoerceToDomain *) node;
 
+		LockNotPinnedObject(TypeRelationId, cd->resulttype);
 		add_object_address(TypeRelationId, cd->resulttype, 0,
 						   context->addrs);
 	}
@@ -2079,6 +2235,7 @@ find_expr_references_walker(Node *node,
 	{
 		NextValueExpr *nve = (NextValueExpr *) node;
 
+		LockNotPinnedObject(RelationRelationId, nve->seqid);
 		add_object_address(RelationRelationId, nve->seqid, 0,
 						   context->addrs);
 	}
@@ -2087,19 +2244,26 @@ find_expr_references_walker(Node *node,
 		OnConflictExpr *onconflict = (OnConflictExpr *) node;
 
 		if (OidIsValid(onconflict->constraint))
+		{
+			LockNotPinnedObject(ConstraintRelationId, onconflict->constraint);
 			add_object_address(ConstraintRelationId, onconflict->constraint, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SortGroupClause))
 	{
 		SortGroupClause *sgc = (SortGroupClause *) node;
 
+		LockNotPinnedObject(OperatorRelationId, sgc->eqop);
 		add_object_address(OperatorRelationId, sgc->eqop, 0,
 						   context->addrs);
 		if (OidIsValid(sgc->sortop))
+		{
+			LockNotPinnedObject(OperatorRelationId, sgc->sortop);
 			add_object_address(OperatorRelationId, sgc->sortop, 0,
 							   context->addrs);
+		}
 		return false;
 	}
 	else if (IsA(node, WindowClause))
@@ -2107,15 +2271,24 @@ find_expr_references_walker(Node *node,
 		WindowClause *wc = (WindowClause *) node;
 
 		if (OidIsValid(wc->startInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->startInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->startInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->endInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->endInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->endInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->inRangeColl) &&
 			wc->inRangeColl != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, wc->inRangeColl);
 			add_object_address(CollationRelationId, wc->inRangeColl, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, CTECycleClause))
@@ -2123,14 +2296,23 @@ find_expr_references_walker(Node *node,
 		CTECycleClause *cc = (CTECycleClause *) node;
 
 		if (OidIsValid(cc->cycle_mark_type))
+		{
+			LockNotPinnedObject(TypeRelationId, cc->cycle_mark_type);
 			add_object_address(TypeRelationId, cc->cycle_mark_type, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_collation))
+		{
+			LockNotPinnedObject(CollationRelationId, cc->cycle_mark_collation);
 			add_object_address(CollationRelationId, cc->cycle_mark_collation, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_neop))
+		{
+			LockNotPinnedObject(OperatorRelationId, cc->cycle_mark_neop);
 			add_object_address(OperatorRelationId, cc->cycle_mark_neop, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, Query))
@@ -2163,6 +2345,7 @@ find_expr_references_walker(Node *node,
 			switch (rte->rtekind)
 			{
 				case RTE_RELATION:
+					LockNotPinnedObject(RelationRelationId, rte->relid);
 					add_object_address(RelationRelationId, rte->relid, 0,
 									   context->addrs);
 					break;
@@ -2215,12 +2398,18 @@ find_expr_references_walker(Node *node,
 			rte = rt_fetch(query->resultRelation, query->rtable);
 			if (rte->rtekind == RTE_RELATION)
 			{
+				bool	locked = false;
 				foreach(lc, query->targetList)
 				{
 					TargetEntry *tle = (TargetEntry *) lfirst(lc);
 
 					if (tle->resjunk)
 						continue;	/* ignore junk tlist items */
+					if (!locked)
+					{
+						LockNotPinnedObject(RelationRelationId, rte->relid);
+						locked = true;
+					}
 					add_object_address(RelationRelationId, rte->relid, tle->resno,
 									   context->addrs);
 				}
@@ -2232,6 +2421,7 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(lc, query->constraintDeps)
 		{
+			LockNotPinnedObject(ConstraintRelationId, lfirst_oid(lc));
 			add_object_address(ConstraintRelationId, lfirst_oid(lc), 0,
 							   context->addrs);
 		}
@@ -2266,16 +2456,25 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, rtfunc->funccoltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, rtfunc->funccolcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool	locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableFunc))
@@ -2288,22 +2487,32 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, tf->coltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, tf->colcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool 	locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableSampleClause))
 	{
 		TableSampleClause *tsc = (TableSampleClause *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, tsc->tsmhandler);
 		add_object_address(ProcedureRelationId, tsc->tsmhandler, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -2354,9 +2563,12 @@ process_function_rte_ref(RangeTblEntry *rte, AttrNumber attnum,
 
 				Assert(attnum - atts_done <= tupdesc->natts);
 				if (OidIsValid(reltype))	/* can this fail? */
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
 					add_object_address(RelationRelationId, reltype,
 									   attnum - atts_done,
 									   context->addrs);
+				}
 				return;
 			}
 			/* Nothing to do; function's result type is handled elsewhere */
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index 00074c8a94..1266101d90 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -844,6 +844,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		/* Add dependency info */
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId, attr->atttypid);
+		LockNotPinnedObject(TypeRelationId, attr->atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -852,6 +853,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 attr->attcollation);
+			LockNotPinnedObject(CollationRelationId, attr->attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1459,11 +1461,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1477,6 +1481,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3391,6 +3396,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3398,6 +3404,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index a819b4197c..d6d1abfcf5 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1116,6 +1116,7 @@ index_create(Relation heapRelation,
 		else
 		{
 			bool		have_simple_col = false;
+			bool		locked_object = false;
 
 			addrs = new_object_addresses();
 
@@ -1128,6 +1129,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					if (!locked_object)
+					{
+						LockNotPinnedObject(RelationRelationId, heapRelationId);
+						locked_object = true;
+					}
 					have_simple_col = true;
 				}
 			}
@@ -1143,6 +1150,8 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				LockNotPinnedObject(RelationRelationId, heapRelationId);
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1158,9 +1167,13 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			LockNotPinnedObject(RelationRelationId, parentIndexRelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			LockNotPinnedObject(RelationRelationId, heapRelationId);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1176,6 +1189,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1184,6 +1198,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1988,6 +2003,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -1999,9 +2022,12 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(heapRelation));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 2983b9180f..d3af0ae726 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949..a47e3c5507 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d..dcce454f00 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d51..d3707e424c 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f701229..78498b8c20 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 3baf9231ed..c4cdbd7c58 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -252,17 +252,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (constraintNTotalKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < constraintNTotalKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, relId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			LockNotPinnedObject(RelationRelationId, relId);
 		}
 	}
 
@@ -275,6 +284,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -294,17 +304,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (foreignNKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < foreignNKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, foreignRelId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			LockNotPinnedObject(RelationRelationId, foreignRelId);
 		}
 	}
 
@@ -320,6 +339,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		LockNotPinnedObject(RelationRelationId, indexRelId);
 	}
 
 	if (foreignNKeys > 0)
@@ -339,15 +359,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -858,9 +881,12 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac..25881654d6 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index cfd7ef51df..ebca5a452b 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,21 +20,21 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
-
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
  * The first argument is the dependent object, the second the one it
@@ -100,6 +100,37 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		if (!isObjectPinned(referenced))
+		{
+			if (referenced->classId != RelationRelationId)
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag,
+								   MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId,
+								   0);
+				/* assert the referenced object is locked */
+				Assert(LockHeldByMe(&tag, AccessShareLock, false));
+			}
+			else
+			{
+				Assert(!IsSharedRelation(referenced->objectId));
+
+				/*
+				 * Assert the referenced object is locked if it should be
+				 * visible (see the comment related to LockNotPinnedObject()
+				 * in TypeCreate()).
+				 */
+				Assert(!ObjectByIdExist(referenced) ||
+					   CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -239,6 +270,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -706,7 +738,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a..e8374eec88 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f..116e524390 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 0602398a54..b44a7f9d78 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -438,10 +438,13 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	LockNotPinnedObject(RelationRelationId, relid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -454,6 +457,8 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	for (int i = 0; i < natts; i++)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, attarray[i]);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -661,10 +666,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba410..e5b5a0b6f8 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed8..82ee7bc2e3 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,37 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid not added to pg_class yet (In heap_create_with_catalog(),
+		 * AddNewRelationType() is called before AddNewRelationTuple()).
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +543,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 738bc46ae8..a4d8342ca1 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -367,6 +367,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		LockNotPinnedObject(RelationRelationId, relOid);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb447..57e86f576a 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -807,6 +810,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc..8616a7c9fa 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 78f96789b0..fb95d17738 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1272,6 +1272,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1280,6 +1281,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1381,6 +1384,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r1);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1389,6 +1394,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r2);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index 7a5ed6b985..8d0cdec59e 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index 1643c8c69a..669a5d6dd8 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -1924,6 +1924,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -1932,6 +1933,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -2968,6 +2970,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3258,6 +3261,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3414,6 +3418,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1f..735bca486c 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 6593fd7d81..8207ef08b3 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1446,6 +1446,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1459,6 +1460,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1962,21 +1964,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 2caab88aa5..e6ff8476e8 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4380,8 +4380,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			LockNotPinnedObject(RelationRelationId, parentOid);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			LockNotPinnedObject(RelationRelationId, partitionIdx->rd_index->indrelid);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5..e70afd216c 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 5872a3e192..58a69e7cc2 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba824..9da98cbeec 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017e..fadfd9064f 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index 9f28d40466..c0634d0af9 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1688,6 +1688,8 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(tablerel));
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d2..9f0b03388a 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -88,6 +88,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	bool		build_mcv;
 	bool		build_expressions;
 	bool		requested_type = false;
+	bool		locked_object = false;
 	int			i;
 	ListCell   *cell;
 	ListCell   *cell2;
@@ -536,6 +537,12 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		if (!locked_object)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked_object = true;
+		}
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +560,8 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +582,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index dbfe0d6b1c..fc7ddf0968 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3419,6 +3419,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, parentOid);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7342,7 +7343,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10167,6 +10170,7 @@ addFkRecurseReferenced(List **wqueue, Constraint *fkconstraint, Relation rel,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+		LockNotPinnedObject(ConstraintRelationId, parentConstr);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
 	}
 
@@ -10458,8 +10462,11 @@ addFkRecurseReferencing(List **wqueue, Constraint *fkconstraint, Relation rel,
 			 */
 			ObjectAddressSet(address, ConstraintRelationId, constrOid);
 			ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, partitionId);
+
+			LockNotPinnedObject(RelationRelationId, partitionId);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 			/* Make all this visible before recursing */
@@ -10960,9 +10967,12 @@ CloneFkReferencing(List **wqueue, Relation parentRel, Relation partRel)
 		/* Set up partition dependencies for the new constraint */
 		ObjectAddressSet(address, ConstraintRelationId, constrOid);
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrOid);
+		LockDatabaseObject(ConstraintRelationId, parentConstrOid, 0, AccessShareLock);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(partRel));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(partRel));
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 		/* Done with the cloned constraint's tuple */
@@ -13248,7 +13258,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -14810,6 +14822,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -14829,6 +14842,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -16428,6 +16442,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17186,14 +17201,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 		CatalogTupleUpdate(classRel, &classTup->t_self, classTup);
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
-								relOid,
-								NamespaceRelationId,
-								oldNspOid,
-								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
+									relOid,
+									NamespaceRelationId,
+									oldNspOid,
+									newNspOid) != 1)
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	if (!already_done)
 	{
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 170360edda..1250673b16 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1018,8 +1018,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1027,6 +1025,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1045,6 +1050,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1058,6 +1064,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1070,6 +1077,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1077,6 +1086,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			LockNotPinnedObject(RelationRelationId, constrrelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1091,6 +1102,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1100,8 +1112,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1110,12 +1125,19 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	if (columns != NULL)
 	{
 		int			i;
+		bool		locked_object = false;
 
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			if (!locked_object)
+			{
+				LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
+				locked_object = true;
+			}
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1255,9 +1277,12 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e..1b90e187ea 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,48 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsstart - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsstart - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prstoken - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prstoken - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsend - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsend - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsheadline - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsheadline - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prslextype - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prslextype - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +495,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -723,6 +748,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +759,23 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmplinit - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmplinit - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmpllexize - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmpllexize - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -998,6 +1032,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1063,6 +1101,7 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = cfgmap->mapseqno;
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = cfgmap->mapdict;
 
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 			ExecStoreVirtualTuple(slot[slot_stored_count]);
 			slot_stored_count++;
 
@@ -1156,9 +1195,13 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
+	ScanKeyData skey;
+	SysScanDesc scan;
+	HeapTuple	maptup;
 
 	/* Find the configuration */
 	tup = GetTSConfigTuple(stmt->cfgname);
@@ -1168,7 +1211,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1227,28 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+
+	ScanKeyInit(&skey,
+				Anum_pg_ts_config_map_mapcfg,
+				BTEqualStrategyNumber, F_OIDEQ,
+				ObjectIdGetDatum(cfgId));
+
+	scan = systable_beginscan(relMap, TSConfigMapIndexId, true,
+							  NULL, 1, &skey);
+
+	while (HeapTupleIsValid((maptup = systable_getnext(scan))))
+	{
+		Form_pg_ts_config_map cfgmap = (Form_pg_ts_config_map) GETSTRUCT(maptup);
+
+		LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
+	}
+
+	systable_endscan(scan);
+
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1480,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1524,9 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				/* Lock dependent objects */
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a1e713335..9febaa24a7 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2672,6 +2674,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4276,10 +4317,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4571,6 +4615,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4619,6 +4664,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bf..c930eca262 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, eventrel_oid);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1..60e8539fe3 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 6908ca7180..0546bcbe16 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,8 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -172,6 +174,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..56f746264b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 6da98cffac..ef6a7075bc 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -117,3 +117,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/modules/test_oat_hooks/expected/alter_table.out b/src/test/modules/test_oat_hooks/expected/alter_table.out
index 8cbacca2c9..df8d276dfc 100644
--- a/src/test/modules/test_oat_hooks/expected/alter_table.out
+++ b/src/test/modules/test_oat_hooks/expected/alter_table.out
@@ -37,6 +37,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE RULE test_oat_notify AS
   ON UPDATE TO test_oat_schema.test_oat_tab
@@ -62,8 +64,6 @@ BEGIN
   END IF;
 END; $$;
 NOTICE:  in process utility: superuser attempting CREATE FUNCTION
-NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
-NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [explicit]
 NOTICE:  in object access: superuser finished create (subId=0x0) [explicit]
 NOTICE:  in process utility: superuser finished CREATE FUNCTION
diff --git a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
index effdc49145..da6d931994 100644
--- a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
+++ b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
@@ -86,6 +86,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE INDEX regress_test_table_t_idx ON regress_test_table (t);
 NOTICE:  in process utility: superuser attempting CREATE INDEX
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 673361e840..c2115ea601 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2867,11 +2867,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-01 09:39                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-02 05:56                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-10 07:31                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-08-19 15:35                                                                       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-10-28 09:30                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-08-19 15:35 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, Jul 10, 2024 at 07:31:06AM +0000, Bertrand Drouvot wrote:
> So, to sum up:
> 
> A. Locking is now done exclusively with LockNotPinnedObject(Oid classid, Oid objid)
> so that it's now always clear what object we want to acquire a lock for. It means
> we are not manipulating directly an object address or a list of objects address
> as it was the case when the locking was done "directly" within the dependency code.
> 
> B. A special case is done for objects that belong to the RelationRelationId class.
> For those, we should be in one of the two following cases that would already
> prevent the relation to be dropped:
> 
>  1. The relation is already locked (could be an existing relation or a relation
>  that we are creating).
> 
>  2. The relation is protected indirectly (i.e an index protected by a lock on
>  its table, a table protected by a lock on a function that depends the table...)
> 
> To avoid any risks for the RelationRelationId class case, we acquire a lock if
> there is none. That may add unnecessary lock for 2. but that seems worth it. 
> 

Please find attached v16, mandatory rebase due to 80ffcb8427.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v16-0001-Avoid-orphaned-objects-dependencies.patch (113.5K, ../../ZsNmMhx%2FrLb0r5iS@ip-10-97-1-34.eu-west-3.compute.internal/2-v16-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 79c81071b061466ef51ca863d1b0189298430984 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v16] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch takes into account any type of objects except the ones that are pinned
(they are not droppable because the system requires it).

A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that's worth it.

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 212 ++++++++++++++++++
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  26 +++
 src/backend/catalog/objectaddress.c           |  57 +++++
 src/backend/catalog/pg_aggregate.c            |   9 +
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  26 +++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  40 +++-
 src/backend/catalog/pg_operator.c             |  19 ++
 src/backend/catalog/pg_proc.c                 |  17 +-
 src/backend/catalog/pg_publication.c          |  11 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  39 ++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   7 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 ++
 src/backend/commands/operatorcmds.c           |  30 +++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   2 +
 src/backend/commands/statscmds.c              |  10 +
 src/backend/commands/tablecmds.c              |  34 ++-
 src/backend/commands/trigger.c                |  29 ++-
 src/backend/commands/tsearchcmds.c            |  73 +++++-
 src/backend/commands/typecmds.c               |  84 +++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   3 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 +++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++
 .../test_oat_hooks/expected/alter_table.out   |   4 +-
 .../expected/test_oat_hooks.out               |   2 +
 src/test/regress/expected/alter_table.out     |  11 +-
 46 files changed, 1015 insertions(+), 25 deletions(-)
  39.7% src/backend/catalog/
  30.4% src/backend/commands/
  16.7% src/test/isolation/expected/
  10.4% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index a44ccee3b6..9a24872a30 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1413,6 +1413,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 0489cbabcb..a3770d7206 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,81 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description = NULL;
+
+	if (isObjectPinned(object))
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	if (object->classId == RelationRelationId)
+	{
+		Assert(!IsSharedRelation(object->objectId));
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+	}
+	else
+	{
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1730,6 +1805,7 @@ find_expr_references_walker(Node *node,
 		if (rte->rtekind == RTE_RELATION)
 		{
 			/* If it's a plain relation, reference this column */
+			LockNotPinnedObject(RelationRelationId, rte->relid);
 			add_object_address(RelationRelationId, rte->relid, var->varattno,
 							   context->addrs);
 		}
@@ -1756,6 +1832,7 @@ find_expr_references_walker(Node *node,
 		Oid			objoid;
 
 		/* A constant must depend on the constant's datatype */
+		LockNotPinnedObject(TypeRelationId, con->consttype);
 		add_object_address(TypeRelationId, con->consttype, 0,
 						   context->addrs);
 
@@ -1767,8 +1844,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (OidIsValid(con->constcollid) &&
 			con->constcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, con->constcollid);
 			add_object_address(CollationRelationId, con->constcollid, 0,
 							   context->addrs);
+		}
 
 		/*
 		 * If it's a regclass or similar literal referring to an existing
@@ -1785,59 +1865,83 @@ find_expr_references_walker(Node *node,
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(PROCOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(ProcedureRelationId, objoid);
 						add_object_address(ProcedureRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGOPEROID:
 				case REGOPERATOROID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(OPEROID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(OperatorRelationId, objoid);
 						add_object_address(OperatorRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCLASSOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(RELOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(RelationRelationId, objoid);
 						add_object_address(RelationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGTYPEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TYPEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TypeRelationId, objoid);
 						add_object_address(TypeRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCOLLATIONOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(COLLOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(CollationRelationId, objoid);
 						add_object_address(CollationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCONFIGOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSCONFIGOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSConfigRelationId, objoid);
 						add_object_address(TSConfigRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGDICTIONARYOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSDICTOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSDictionaryRelationId, objoid);
 						add_object_address(TSDictionaryRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 				case REGNAMESPACEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(NAMESPACEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(NamespaceRelationId, objoid);
 						add_object_address(NamespaceRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 					/*
@@ -1859,18 +1963,23 @@ find_expr_references_walker(Node *node,
 		Param	   *param = (Param *) node;
 
 		/* A parameter must depend on the parameter's datatype */
+		LockNotPinnedObject(TypeRelationId, param->paramtype);
 		add_object_address(TypeRelationId, param->paramtype, 0,
 						   context->addrs);
 		/* and its collation, just as for Consts */
 		if (OidIsValid(param->paramcollid) &&
 			param->paramcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, param->paramcollid);
 			add_object_address(CollationRelationId, param->paramcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FuncExpr))
 	{
 		FuncExpr   *funcexpr = (FuncExpr *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, funcexpr->funcid);
 		add_object_address(ProcedureRelationId, funcexpr->funcid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1879,6 +1988,7 @@ find_expr_references_walker(Node *node,
 	{
 		OpExpr	   *opexpr = (OpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1887,6 +1997,7 @@ find_expr_references_walker(Node *node,
 	{
 		DistinctExpr *distinctexpr = (DistinctExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, distinctexpr->opno);
 		add_object_address(OperatorRelationId, distinctexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1895,6 +2006,7 @@ find_expr_references_walker(Node *node,
 	{
 		NullIfExpr *nullifexpr = (NullIfExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, nullifexpr->opno);
 		add_object_address(OperatorRelationId, nullifexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1903,6 +2015,7 @@ find_expr_references_walker(Node *node,
 	{
 		ScalarArrayOpExpr *opexpr = (ScalarArrayOpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1911,6 +2024,7 @@ find_expr_references_walker(Node *node,
 	{
 		Aggref	   *aggref = (Aggref *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, aggref->aggfnoid);
 		add_object_address(ProcedureRelationId, aggref->aggfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1919,6 +2033,7 @@ find_expr_references_walker(Node *node,
 	{
 		WindowFunc *wfunc = (WindowFunc *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, wfunc->winfnoid);
 		add_object_address(ProcedureRelationId, wfunc->winfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1935,8 +2050,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (sbsref->refrestype != sbsref->refcontainertype &&
 			sbsref->refrestype != sbsref->refelemtype)
+		{
+			LockNotPinnedObject(TypeRelationId, sbsref->refrestype);
 			add_object_address(TypeRelationId, sbsref->refrestype, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SubPlan))
@@ -1960,16 +2078,25 @@ find_expr_references_walker(Node *node,
 		 * anywhere else in the expression.
 		 */
 		if (OidIsValid(reltype))
+		{
+			LockNotPinnedObject(RelationRelationId, reltype);
 			add_object_address(RelationRelationId, reltype, fselect->fieldnum,
 							   context->addrs);
+		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fselect->resulttype);
 			add_object_address(TypeRelationId, fselect->resulttype, 0,
 							   context->addrs);
+		}
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(fselect->resultcollid) &&
 			fselect->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, fselect->resultcollid);
 			add_object_address(CollationRelationId, fselect->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FieldStore))
 	{
@@ -1980,53 +2107,76 @@ find_expr_references_walker(Node *node,
 		if (OidIsValid(reltype))
 		{
 			ListCell   *l;
+			bool	locked = false;
 
 			foreach(l, fstore->fieldnums)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
+					locked = true;
+				}
 				add_object_address(RelationRelationId, reltype, lfirst_int(l),
 								   context->addrs);
+			}
 		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fstore->resulttype);
 			add_object_address(TypeRelationId, fstore->resulttype, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, RelabelType))
 	{
 		RelabelType *relab = (RelabelType *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, relab->resulttype);
 		add_object_address(TypeRelationId, relab->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(relab->resultcollid) &&
 			relab->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, relab->resultcollid);
 			add_object_address(CollationRelationId, relab->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, CoerceViaIO))
 	{
 		CoerceViaIO *iocoerce = (CoerceViaIO *) node;
 
 		/* since there is no exposed function, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, iocoerce->resulttype);
 		add_object_address(TypeRelationId, iocoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(iocoerce->resultcollid) &&
 			iocoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, iocoerce->resultcollid);
 			add_object_address(CollationRelationId, iocoerce->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, ArrayCoerceExpr))
 	{
 		ArrayCoerceExpr *acoerce = (ArrayCoerceExpr *) node;
 
 		/* as above, depend on type */
+		LockNotPinnedObject(TypeRelationId, acoerce->resulttype);
 		add_object_address(TypeRelationId, acoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(acoerce->resultcollid) &&
 			acoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, acoerce->resultcollid);
 			add_object_address(CollationRelationId, acoerce->resultcollid, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, ConvertRowtypeExpr))
@@ -2034,6 +2184,7 @@ find_expr_references_walker(Node *node,
 		ConvertRowtypeExpr *cvt = (ConvertRowtypeExpr *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, cvt->resulttype);
 		add_object_address(TypeRelationId, cvt->resulttype, 0,
 						   context->addrs);
 	}
@@ -2041,6 +2192,7 @@ find_expr_references_walker(Node *node,
 	{
 		CollateExpr *coll = (CollateExpr *) node;
 
+		LockNotPinnedObject(CollationRelationId, coll->collOid);
 		add_object_address(CollationRelationId, coll->collOid, 0,
 						   context->addrs);
 	}
@@ -2048,6 +2200,7 @@ find_expr_references_walker(Node *node,
 	{
 		RowExpr    *rowexpr = (RowExpr *) node;
 
+		LockNotPinnedObject(TypeRelationId, rowexpr->row_typeid);
 		add_object_address(TypeRelationId, rowexpr->row_typeid, 0,
 						   context->addrs);
 	}
@@ -2058,11 +2211,13 @@ find_expr_references_walker(Node *node,
 
 		foreach(l, rcexpr->opnos)
 		{
+			LockNotPinnedObject(OperatorRelationId, lfirst_oid(l));
 			add_object_address(OperatorRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
 		foreach(l, rcexpr->opfamilies)
 		{
+			LockNotPinnedObject(OperatorFamilyRelationId, lfirst_oid(l));
 			add_object_address(OperatorFamilyRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
@@ -2072,6 +2227,7 @@ find_expr_references_walker(Node *node,
 	{
 		CoerceToDomain *cd = (CoerceToDomain *) node;
 
+		LockNotPinnedObject(TypeRelationId, cd->resulttype);
 		add_object_address(TypeRelationId, cd->resulttype, 0,
 						   context->addrs);
 	}
@@ -2079,6 +2235,7 @@ find_expr_references_walker(Node *node,
 	{
 		NextValueExpr *nve = (NextValueExpr *) node;
 
+		LockNotPinnedObject(RelationRelationId, nve->seqid);
 		add_object_address(RelationRelationId, nve->seqid, 0,
 						   context->addrs);
 	}
@@ -2087,19 +2244,26 @@ find_expr_references_walker(Node *node,
 		OnConflictExpr *onconflict = (OnConflictExpr *) node;
 
 		if (OidIsValid(onconflict->constraint))
+		{
+			LockNotPinnedObject(ConstraintRelationId, onconflict->constraint);
 			add_object_address(ConstraintRelationId, onconflict->constraint, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SortGroupClause))
 	{
 		SortGroupClause *sgc = (SortGroupClause *) node;
 
+		LockNotPinnedObject(OperatorRelationId, sgc->eqop);
 		add_object_address(OperatorRelationId, sgc->eqop, 0,
 						   context->addrs);
 		if (OidIsValid(sgc->sortop))
+		{
+			LockNotPinnedObject(OperatorRelationId, sgc->sortop);
 			add_object_address(OperatorRelationId, sgc->sortop, 0,
 							   context->addrs);
+		}
 		return false;
 	}
 	else if (IsA(node, WindowClause))
@@ -2107,15 +2271,24 @@ find_expr_references_walker(Node *node,
 		WindowClause *wc = (WindowClause *) node;
 
 		if (OidIsValid(wc->startInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->startInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->startInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->endInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->endInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->endInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->inRangeColl) &&
 			wc->inRangeColl != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, wc->inRangeColl);
 			add_object_address(CollationRelationId, wc->inRangeColl, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, CTECycleClause))
@@ -2123,14 +2296,23 @@ find_expr_references_walker(Node *node,
 		CTECycleClause *cc = (CTECycleClause *) node;
 
 		if (OidIsValid(cc->cycle_mark_type))
+		{
+			LockNotPinnedObject(TypeRelationId, cc->cycle_mark_type);
 			add_object_address(TypeRelationId, cc->cycle_mark_type, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_collation))
+		{
+			LockNotPinnedObject(CollationRelationId, cc->cycle_mark_collation);
 			add_object_address(CollationRelationId, cc->cycle_mark_collation, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_neop))
+		{
+			LockNotPinnedObject(OperatorRelationId, cc->cycle_mark_neop);
 			add_object_address(OperatorRelationId, cc->cycle_mark_neop, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, Query))
@@ -2163,6 +2345,7 @@ find_expr_references_walker(Node *node,
 			switch (rte->rtekind)
 			{
 				case RTE_RELATION:
+					LockNotPinnedObject(RelationRelationId, rte->relid);
 					add_object_address(RelationRelationId, rte->relid, 0,
 									   context->addrs);
 					break;
@@ -2215,12 +2398,18 @@ find_expr_references_walker(Node *node,
 			rte = rt_fetch(query->resultRelation, query->rtable);
 			if (rte->rtekind == RTE_RELATION)
 			{
+				bool	locked = false;
 				foreach(lc, query->targetList)
 				{
 					TargetEntry *tle = (TargetEntry *) lfirst(lc);
 
 					if (tle->resjunk)
 						continue;	/* ignore junk tlist items */
+					if (!locked)
+					{
+						LockNotPinnedObject(RelationRelationId, rte->relid);
+						locked = true;
+					}
 					add_object_address(RelationRelationId, rte->relid, tle->resno,
 									   context->addrs);
 				}
@@ -2232,6 +2421,7 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(lc, query->constraintDeps)
 		{
+			LockNotPinnedObject(ConstraintRelationId, lfirst_oid(lc));
 			add_object_address(ConstraintRelationId, lfirst_oid(lc), 0,
 							   context->addrs);
 		}
@@ -2266,16 +2456,25 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, rtfunc->funccoltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, rtfunc->funccolcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool	locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableFunc))
@@ -2288,22 +2487,32 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, tf->coltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, tf->colcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool 	locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableSampleClause))
 	{
 		TableSampleClause *tsc = (TableSampleClause *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, tsc->tsmhandler);
 		add_object_address(ProcedureRelationId, tsc->tsmhandler, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -2354,9 +2563,12 @@ process_function_rte_ref(RangeTblEntry *rte, AttrNumber attnum,
 
 				Assert(attnum - atts_done <= tupdesc->natts);
 				if (OidIsValid(reltype))	/* can this fail? */
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
 					add_object_address(RelationRelationId, reltype,
 									   attnum - atts_done,
 									   context->addrs);
+				}
 				return;
 			}
 			/* Nothing to do; function's result type is handled elsewhere */
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index 01b43cc6a8..97600e7a3b 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -844,6 +844,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		/* Add dependency info */
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId, attr->atttypid);
+		LockNotPinnedObject(TypeRelationId, attr->atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -852,6 +853,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 attr->attcollation);
+			LockNotPinnedObject(CollationRelationId, attr->attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1459,11 +1461,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1477,6 +1481,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3391,6 +3396,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3398,6 +3404,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index a819b4197c..d6d1abfcf5 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1116,6 +1116,7 @@ index_create(Relation heapRelation,
 		else
 		{
 			bool		have_simple_col = false;
+			bool		locked_object = false;
 
 			addrs = new_object_addresses();
 
@@ -1128,6 +1129,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					if (!locked_object)
+					{
+						LockNotPinnedObject(RelationRelationId, heapRelationId);
+						locked_object = true;
+					}
 					have_simple_col = true;
 				}
 			}
@@ -1143,6 +1150,8 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				LockNotPinnedObject(RelationRelationId, heapRelationId);
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1158,9 +1167,13 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			LockNotPinnedObject(RelationRelationId, parentIndexRelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			LockNotPinnedObject(RelationRelationId, heapRelationId);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1176,6 +1189,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1184,6 +1198,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1988,6 +2003,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -1999,9 +2022,12 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(heapRelation));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 85a7b7e641..17c4085948 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949..a47e3c5507 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d..dcce454f00 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d51..d3707e424c 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f701229..78498b8c20 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 3baf9231ed..c4cdbd7c58 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -252,17 +252,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (constraintNTotalKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < constraintNTotalKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, relId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			LockNotPinnedObject(RelationRelationId, relId);
 		}
 	}
 
@@ -275,6 +284,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -294,17 +304,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (foreignNKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < foreignNKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, foreignRelId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			LockNotPinnedObject(RelationRelationId, foreignRelId);
 		}
 	}
 
@@ -320,6 +339,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		LockNotPinnedObject(RelationRelationId, indexRelId);
 	}
 
 	if (foreignNKeys > 0)
@@ -339,15 +359,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -858,9 +881,12 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac..25881654d6 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index cfd7ef51df..ebca5a452b 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,21 +20,21 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
-
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
  * The first argument is the dependent object, the second the one it
@@ -100,6 +100,37 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		if (!isObjectPinned(referenced))
+		{
+			if (referenced->classId != RelationRelationId)
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag,
+								   MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId,
+								   0);
+				/* assert the referenced object is locked */
+				Assert(LockHeldByMe(&tag, AccessShareLock, false));
+			}
+			else
+			{
+				Assert(!IsSharedRelation(referenced->objectId));
+
+				/*
+				 * Assert the referenced object is locked if it should be
+				 * visible (see the comment related to LockNotPinnedObject()
+				 * in TypeCreate()).
+				 */
+				Assert(!ObjectByIdExist(referenced) ||
+					   CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -239,6 +270,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -706,7 +738,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a..e8374eec88 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f..116e524390 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 7fe5fe2b86..d533e4fd31 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -395,6 +395,7 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 				referenced;
 	List	   *relids = NIL;
 	int			i;
+	bool		locked = false;
 
 	rel = table_open(PublicationRelRelationId, RowExclusiveLock);
 
@@ -457,10 +458,13 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	LockNotPinnedObject(RelationRelationId, relid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -474,6 +478,11 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	while ((i = bms_next_member(attnums, i)) >= 0)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, i);
+		if (!locked)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked = true;
+		}
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -643,10 +652,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba410..e5b5a0b6f8 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed8..82ee7bc2e3 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,37 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid not added to pg_class yet (In heap_create_with_catalog(),
+		 * AddNewRelationType() is called before AddNewRelationTuple()).
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +543,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 738bc46ae8..a4d8342ca1 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -367,6 +367,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		LockNotPinnedObject(RelationRelationId, relOid);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb447..57e86f576a 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -807,6 +810,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc..8616a7c9fa 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 78f96789b0..fb95d17738 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1272,6 +1272,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1280,6 +1281,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1381,6 +1384,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r1);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1389,6 +1394,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r2);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index 7a5ed6b985..8d0cdec59e 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index 1643c8c69a..669a5d6dd8 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -1924,6 +1924,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -1932,6 +1933,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -2968,6 +2970,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3258,6 +3261,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3414,6 +3418,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1f..735bca486c 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 6593fd7d81..8207ef08b3 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1446,6 +1446,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1459,6 +1460,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1962,21 +1964,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index c5a56c75f6..fc7a28baf9 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4384,8 +4384,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			LockNotPinnedObject(RelationRelationId, parentOid);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			LockNotPinnedObject(RelationRelationId, partitionIdx->rd_index->indrelid);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5..e70afd216c 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 5872a3e192..58a69e7cc2 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba824..9da98cbeec 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017e..fadfd9064f 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index 8c1131f020..b94677ae65 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1688,6 +1688,8 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(tablerel));
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d2..9f0b03388a 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -88,6 +88,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	bool		build_mcv;
 	bool		build_expressions;
 	bool		requested_type = false;
+	bool		locked_object = false;
 	int			i;
 	ListCell   *cell;
 	ListCell   *cell2;
@@ -536,6 +537,12 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		if (!locked_object)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked_object = true;
+		}
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +560,8 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +582,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 7a36db6af6..ff605bd0ff 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3419,6 +3419,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, parentOid);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7349,7 +7350,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10174,6 +10177,7 @@ addFkRecurseReferenced(List **wqueue, Constraint *fkconstraint, Relation rel,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+		LockNotPinnedObject(ConstraintRelationId, parentConstr);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
 	}
 
@@ -10465,8 +10469,11 @@ addFkRecurseReferencing(List **wqueue, Constraint *fkconstraint, Relation rel,
 			 */
 			ObjectAddressSet(address, ConstraintRelationId, constrOid);
 			ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, partitionId);
+
+			LockNotPinnedObject(RelationRelationId, partitionId);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 			/* Make all this visible before recursing */
@@ -10984,9 +10991,12 @@ CloneFkReferencing(List **wqueue, Relation parentRel, Relation partRel)
 		/* Set up partition dependencies for the new constraint */
 		ObjectAddressSet(address, ConstraintRelationId, constrOid);
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrOid);
+		LockDatabaseObject(ConstraintRelationId, parentConstrOid, 0, AccessShareLock);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(partRel));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(partRel));
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 		/* Done with the cloned constraint's tuple */
@@ -13272,7 +13282,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -14834,6 +14846,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -14853,6 +14866,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -16452,6 +16466,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17210,14 +17225,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 		CatalogTupleUpdate(classRel, &classTup->t_self, classTup);
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
-								relOid,
-								NamespaceRelationId,
-								oldNspOid,
-								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
+									relOid,
+									NamespaceRelationId,
+									oldNspOid,
+									newNspOid) != 1)
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	if (!already_done)
 	{
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 170360edda..1250673b16 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1018,8 +1018,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1027,6 +1025,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1045,6 +1050,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1058,6 +1064,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1070,6 +1077,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1077,6 +1086,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			LockNotPinnedObject(RelationRelationId, constrrelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1091,6 +1102,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1100,8 +1112,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1110,12 +1125,19 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	if (columns != NULL)
 	{
 		int			i;
+		bool		locked_object = false;
 
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			if (!locked_object)
+			{
+				LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
+				locked_object = true;
+			}
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1255,9 +1277,12 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e..1b90e187ea 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,48 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsstart - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsstart - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prstoken - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prstoken - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsend - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsend - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsheadline - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsheadline - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prslextype - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prslextype - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +495,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -723,6 +748,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +759,23 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmplinit - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmplinit - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmpllexize - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmpllexize - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -998,6 +1032,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1063,6 +1101,7 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = cfgmap->mapseqno;
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = cfgmap->mapdict;
 
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 			ExecStoreVirtualTuple(slot[slot_stored_count]);
 			slot_stored_count++;
 
@@ -1156,9 +1195,13 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
+	ScanKeyData skey;
+	SysScanDesc scan;
+	HeapTuple	maptup;
 
 	/* Find the configuration */
 	tup = GetTSConfigTuple(stmt->cfgname);
@@ -1168,7 +1211,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1227,28 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+
+	ScanKeyInit(&skey,
+				Anum_pg_ts_config_map_mapcfg,
+				BTEqualStrategyNumber, F_OIDEQ,
+				ObjectIdGetDatum(cfgId));
+
+	scan = systable_beginscan(relMap, TSConfigMapIndexId, true,
+							  NULL, 1, &skey);
+
+	while (HeapTupleIsValid((maptup = systable_getnext(scan))))
+	{
+		Form_pg_ts_config_map cfgmap = (Form_pg_ts_config_map) GETSTRUCT(maptup);
+
+		LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
+	}
+
+	systable_endscan(scan);
+
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1480,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1524,9 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				/* Lock dependent objects */
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a1e713335..9febaa24a7 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2672,6 +2674,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4276,10 +4317,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4571,6 +4615,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4619,6 +4664,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bf..c930eca262 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, eventrel_oid);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index b43a24d4bc..ae41f3613c 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 6908ca7180..0546bcbe16 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,8 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -172,6 +174,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..56f746264b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 6da98cffac..ef6a7075bc 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -117,3 +117,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/modules/test_oat_hooks/expected/alter_table.out b/src/test/modules/test_oat_hooks/expected/alter_table.out
index 8cbacca2c9..df8d276dfc 100644
--- a/src/test/modules/test_oat_hooks/expected/alter_table.out
+++ b/src/test/modules/test_oat_hooks/expected/alter_table.out
@@ -37,6 +37,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE RULE test_oat_notify AS
   ON UPDATE TO test_oat_schema.test_oat_tab
@@ -62,8 +64,6 @@ BEGIN
   END IF;
 END; $$;
 NOTICE:  in process utility: superuser attempting CREATE FUNCTION
-NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
-NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [explicit]
 NOTICE:  in object access: superuser finished create (subId=0x0) [explicit]
 NOTICE:  in process utility: superuser finished CREATE FUNCTION
diff --git a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
index effdc49145..da6d931994 100644
--- a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
+++ b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
@@ -86,6 +86,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE INDEX regress_test_table_t_idx ON regress_test_table (t);
 NOTICE:  in process utility: superuser attempting CREATE INDEX
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 79cf82b5ae..1ed23c54cb 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2867,11 +2867,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-01 09:39                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-02 05:56                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-10 07:31                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-08-19 15:35                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-10-28 09:30                                                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-01-02 08:15                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2024-10-28 09:30 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Mon, Aug 19, 2024 at 03:35:14PM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Wed, Jul 10, 2024 at 07:31:06AM +0000, Bertrand Drouvot wrote:
> > So, to sum up:
> > 
> > A. Locking is now done exclusively with LockNotPinnedObject(Oid classid, Oid objid)
> > so that it's now always clear what object we want to acquire a lock for. It means
> > we are not manipulating directly an object address or a list of objects address
> > as it was the case when the locking was done "directly" within the dependency code.
> > 
> > B. A special case is done for objects that belong to the RelationRelationId class.
> > For those, we should be in one of the two following cases that would already
> > prevent the relation to be dropped:
> > 
> >  1. The relation is already locked (could be an existing relation or a relation
> >  that we are creating).
> > 
> >  2. The relation is protected indirectly (i.e an index protected by a lock on
> >  its table, a table protected by a lock on a function that depends the table...)
> > 
> > To avoid any risks for the RelationRelationId class case, we acquire a lock if
> > there is none. That may add unnecessary lock for 2. but that seems worth it. 
> > 
> 
> Please find attached v16, mandatory rebase due to 80ffcb8427.

rebased (v17 attached).

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v17-0001-Avoid-orphaned-objects-dependencies.patch (112.3K, ../../Zx9Zq5GeA1hTbAtu@ip-10-97-1-34.eu-west-3.compute.internal/2-v17-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From e08d57be0ae5cfe6713cfa4b241320fffd80f822 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v17] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch takes into account any type of objects except the ones that are pinned
(they are not droppable because the system requires it).

A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that's worth it.

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 212 ++++++++++++++++++
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  26 +++
 src/backend/catalog/objectaddress.c           |  57 +++++
 src/backend/catalog/pg_aggregate.c            |   9 +
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  26 +++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  39 +++-
 src/backend/catalog/pg_operator.c             |  19 ++
 src/backend/catalog/pg_proc.c                 |  17 +-
 src/backend/catalog/pg_publication.c          |  11 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  39 ++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   7 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 ++
 src/backend/commands/operatorcmds.c           |  30 +++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   2 +
 src/backend/commands/statscmds.c              |  10 +
 src/backend/commands/tablecmds.c              |  24 +-
 src/backend/commands/trigger.c                |  29 ++-
 src/backend/commands/tsearchcmds.c            |  73 +++++-
 src/backend/commands/typecmds.c               |  84 +++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   3 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 +++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++
 .../test_oat_hooks/expected/alter_table.out   |   4 +-
 .../expected/test_oat_hooks.out               |   2 +
 src/test/regress/expected/alter_table.out     |  11 +-
 46 files changed, 1009 insertions(+), 20 deletions(-)
  40.0% src/backend/catalog/
  29.8% src/backend/commands/
  16.8% src/test/isolation/expected/
  10.5% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 95eb0b1227..176bd46261 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1414,6 +1414,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 0489cbabcb..a3770d7206 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,81 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description = NULL;
+
+	if (isObjectPinned(object))
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	if (object->classId == RelationRelationId)
+	{
+		Assert(!IsSharedRelation(object->objectId));
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+	}
+	else
+	{
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1730,6 +1805,7 @@ find_expr_references_walker(Node *node,
 		if (rte->rtekind == RTE_RELATION)
 		{
 			/* If it's a plain relation, reference this column */
+			LockNotPinnedObject(RelationRelationId, rte->relid);
 			add_object_address(RelationRelationId, rte->relid, var->varattno,
 							   context->addrs);
 		}
@@ -1756,6 +1832,7 @@ find_expr_references_walker(Node *node,
 		Oid			objoid;
 
 		/* A constant must depend on the constant's datatype */
+		LockNotPinnedObject(TypeRelationId, con->consttype);
 		add_object_address(TypeRelationId, con->consttype, 0,
 						   context->addrs);
 
@@ -1767,8 +1844,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (OidIsValid(con->constcollid) &&
 			con->constcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, con->constcollid);
 			add_object_address(CollationRelationId, con->constcollid, 0,
 							   context->addrs);
+		}
 
 		/*
 		 * If it's a regclass or similar literal referring to an existing
@@ -1785,59 +1865,83 @@ find_expr_references_walker(Node *node,
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(PROCOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(ProcedureRelationId, objoid);
 						add_object_address(ProcedureRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGOPEROID:
 				case REGOPERATOROID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(OPEROID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(OperatorRelationId, objoid);
 						add_object_address(OperatorRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCLASSOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(RELOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(RelationRelationId, objoid);
 						add_object_address(RelationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGTYPEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TYPEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TypeRelationId, objoid);
 						add_object_address(TypeRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCOLLATIONOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(COLLOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(CollationRelationId, objoid);
 						add_object_address(CollationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCONFIGOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSCONFIGOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSConfigRelationId, objoid);
 						add_object_address(TSConfigRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGDICTIONARYOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSDICTOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSDictionaryRelationId, objoid);
 						add_object_address(TSDictionaryRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 				case REGNAMESPACEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(NAMESPACEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(NamespaceRelationId, objoid);
 						add_object_address(NamespaceRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 					/*
@@ -1859,18 +1963,23 @@ find_expr_references_walker(Node *node,
 		Param	   *param = (Param *) node;
 
 		/* A parameter must depend on the parameter's datatype */
+		LockNotPinnedObject(TypeRelationId, param->paramtype);
 		add_object_address(TypeRelationId, param->paramtype, 0,
 						   context->addrs);
 		/* and its collation, just as for Consts */
 		if (OidIsValid(param->paramcollid) &&
 			param->paramcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, param->paramcollid);
 			add_object_address(CollationRelationId, param->paramcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FuncExpr))
 	{
 		FuncExpr   *funcexpr = (FuncExpr *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, funcexpr->funcid);
 		add_object_address(ProcedureRelationId, funcexpr->funcid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1879,6 +1988,7 @@ find_expr_references_walker(Node *node,
 	{
 		OpExpr	   *opexpr = (OpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1887,6 +1997,7 @@ find_expr_references_walker(Node *node,
 	{
 		DistinctExpr *distinctexpr = (DistinctExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, distinctexpr->opno);
 		add_object_address(OperatorRelationId, distinctexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1895,6 +2006,7 @@ find_expr_references_walker(Node *node,
 	{
 		NullIfExpr *nullifexpr = (NullIfExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, nullifexpr->opno);
 		add_object_address(OperatorRelationId, nullifexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1903,6 +2015,7 @@ find_expr_references_walker(Node *node,
 	{
 		ScalarArrayOpExpr *opexpr = (ScalarArrayOpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1911,6 +2024,7 @@ find_expr_references_walker(Node *node,
 	{
 		Aggref	   *aggref = (Aggref *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, aggref->aggfnoid);
 		add_object_address(ProcedureRelationId, aggref->aggfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1919,6 +2033,7 @@ find_expr_references_walker(Node *node,
 	{
 		WindowFunc *wfunc = (WindowFunc *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, wfunc->winfnoid);
 		add_object_address(ProcedureRelationId, wfunc->winfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1935,8 +2050,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (sbsref->refrestype != sbsref->refcontainertype &&
 			sbsref->refrestype != sbsref->refelemtype)
+		{
+			LockNotPinnedObject(TypeRelationId, sbsref->refrestype);
 			add_object_address(TypeRelationId, sbsref->refrestype, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SubPlan))
@@ -1960,16 +2078,25 @@ find_expr_references_walker(Node *node,
 		 * anywhere else in the expression.
 		 */
 		if (OidIsValid(reltype))
+		{
+			LockNotPinnedObject(RelationRelationId, reltype);
 			add_object_address(RelationRelationId, reltype, fselect->fieldnum,
 							   context->addrs);
+		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fselect->resulttype);
 			add_object_address(TypeRelationId, fselect->resulttype, 0,
 							   context->addrs);
+		}
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(fselect->resultcollid) &&
 			fselect->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, fselect->resultcollid);
 			add_object_address(CollationRelationId, fselect->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FieldStore))
 	{
@@ -1980,53 +2107,76 @@ find_expr_references_walker(Node *node,
 		if (OidIsValid(reltype))
 		{
 			ListCell   *l;
+			bool	locked = false;
 
 			foreach(l, fstore->fieldnums)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
+					locked = true;
+				}
 				add_object_address(RelationRelationId, reltype, lfirst_int(l),
 								   context->addrs);
+			}
 		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fstore->resulttype);
 			add_object_address(TypeRelationId, fstore->resulttype, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, RelabelType))
 	{
 		RelabelType *relab = (RelabelType *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, relab->resulttype);
 		add_object_address(TypeRelationId, relab->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(relab->resultcollid) &&
 			relab->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, relab->resultcollid);
 			add_object_address(CollationRelationId, relab->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, CoerceViaIO))
 	{
 		CoerceViaIO *iocoerce = (CoerceViaIO *) node;
 
 		/* since there is no exposed function, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, iocoerce->resulttype);
 		add_object_address(TypeRelationId, iocoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(iocoerce->resultcollid) &&
 			iocoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, iocoerce->resultcollid);
 			add_object_address(CollationRelationId, iocoerce->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, ArrayCoerceExpr))
 	{
 		ArrayCoerceExpr *acoerce = (ArrayCoerceExpr *) node;
 
 		/* as above, depend on type */
+		LockNotPinnedObject(TypeRelationId, acoerce->resulttype);
 		add_object_address(TypeRelationId, acoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(acoerce->resultcollid) &&
 			acoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, acoerce->resultcollid);
 			add_object_address(CollationRelationId, acoerce->resultcollid, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, ConvertRowtypeExpr))
@@ -2034,6 +2184,7 @@ find_expr_references_walker(Node *node,
 		ConvertRowtypeExpr *cvt = (ConvertRowtypeExpr *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, cvt->resulttype);
 		add_object_address(TypeRelationId, cvt->resulttype, 0,
 						   context->addrs);
 	}
@@ -2041,6 +2192,7 @@ find_expr_references_walker(Node *node,
 	{
 		CollateExpr *coll = (CollateExpr *) node;
 
+		LockNotPinnedObject(CollationRelationId, coll->collOid);
 		add_object_address(CollationRelationId, coll->collOid, 0,
 						   context->addrs);
 	}
@@ -2048,6 +2200,7 @@ find_expr_references_walker(Node *node,
 	{
 		RowExpr    *rowexpr = (RowExpr *) node;
 
+		LockNotPinnedObject(TypeRelationId, rowexpr->row_typeid);
 		add_object_address(TypeRelationId, rowexpr->row_typeid, 0,
 						   context->addrs);
 	}
@@ -2058,11 +2211,13 @@ find_expr_references_walker(Node *node,
 
 		foreach(l, rcexpr->opnos)
 		{
+			LockNotPinnedObject(OperatorRelationId, lfirst_oid(l));
 			add_object_address(OperatorRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
 		foreach(l, rcexpr->opfamilies)
 		{
+			LockNotPinnedObject(OperatorFamilyRelationId, lfirst_oid(l));
 			add_object_address(OperatorFamilyRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
@@ -2072,6 +2227,7 @@ find_expr_references_walker(Node *node,
 	{
 		CoerceToDomain *cd = (CoerceToDomain *) node;
 
+		LockNotPinnedObject(TypeRelationId, cd->resulttype);
 		add_object_address(TypeRelationId, cd->resulttype, 0,
 						   context->addrs);
 	}
@@ -2079,6 +2235,7 @@ find_expr_references_walker(Node *node,
 	{
 		NextValueExpr *nve = (NextValueExpr *) node;
 
+		LockNotPinnedObject(RelationRelationId, nve->seqid);
 		add_object_address(RelationRelationId, nve->seqid, 0,
 						   context->addrs);
 	}
@@ -2087,19 +2244,26 @@ find_expr_references_walker(Node *node,
 		OnConflictExpr *onconflict = (OnConflictExpr *) node;
 
 		if (OidIsValid(onconflict->constraint))
+		{
+			LockNotPinnedObject(ConstraintRelationId, onconflict->constraint);
 			add_object_address(ConstraintRelationId, onconflict->constraint, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SortGroupClause))
 	{
 		SortGroupClause *sgc = (SortGroupClause *) node;
 
+		LockNotPinnedObject(OperatorRelationId, sgc->eqop);
 		add_object_address(OperatorRelationId, sgc->eqop, 0,
 						   context->addrs);
 		if (OidIsValid(sgc->sortop))
+		{
+			LockNotPinnedObject(OperatorRelationId, sgc->sortop);
 			add_object_address(OperatorRelationId, sgc->sortop, 0,
 							   context->addrs);
+		}
 		return false;
 	}
 	else if (IsA(node, WindowClause))
@@ -2107,15 +2271,24 @@ find_expr_references_walker(Node *node,
 		WindowClause *wc = (WindowClause *) node;
 
 		if (OidIsValid(wc->startInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->startInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->startInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->endInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->endInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->endInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->inRangeColl) &&
 			wc->inRangeColl != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, wc->inRangeColl);
 			add_object_address(CollationRelationId, wc->inRangeColl, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, CTECycleClause))
@@ -2123,14 +2296,23 @@ find_expr_references_walker(Node *node,
 		CTECycleClause *cc = (CTECycleClause *) node;
 
 		if (OidIsValid(cc->cycle_mark_type))
+		{
+			LockNotPinnedObject(TypeRelationId, cc->cycle_mark_type);
 			add_object_address(TypeRelationId, cc->cycle_mark_type, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_collation))
+		{
+			LockNotPinnedObject(CollationRelationId, cc->cycle_mark_collation);
 			add_object_address(CollationRelationId, cc->cycle_mark_collation, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_neop))
+		{
+			LockNotPinnedObject(OperatorRelationId, cc->cycle_mark_neop);
 			add_object_address(OperatorRelationId, cc->cycle_mark_neop, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, Query))
@@ -2163,6 +2345,7 @@ find_expr_references_walker(Node *node,
 			switch (rte->rtekind)
 			{
 				case RTE_RELATION:
+					LockNotPinnedObject(RelationRelationId, rte->relid);
 					add_object_address(RelationRelationId, rte->relid, 0,
 									   context->addrs);
 					break;
@@ -2215,12 +2398,18 @@ find_expr_references_walker(Node *node,
 			rte = rt_fetch(query->resultRelation, query->rtable);
 			if (rte->rtekind == RTE_RELATION)
 			{
+				bool	locked = false;
 				foreach(lc, query->targetList)
 				{
 					TargetEntry *tle = (TargetEntry *) lfirst(lc);
 
 					if (tle->resjunk)
 						continue;	/* ignore junk tlist items */
+					if (!locked)
+					{
+						LockNotPinnedObject(RelationRelationId, rte->relid);
+						locked = true;
+					}
 					add_object_address(RelationRelationId, rte->relid, tle->resno,
 									   context->addrs);
 				}
@@ -2232,6 +2421,7 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(lc, query->constraintDeps)
 		{
+			LockNotPinnedObject(ConstraintRelationId, lfirst_oid(lc));
 			add_object_address(ConstraintRelationId, lfirst_oid(lc), 0,
 							   context->addrs);
 		}
@@ -2266,16 +2456,25 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, rtfunc->funccoltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, rtfunc->funccolcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool	locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableFunc))
@@ -2288,22 +2487,32 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, tf->coltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, tf->colcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool 	locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableSampleClause))
 	{
 		TableSampleClause *tsc = (TableSampleClause *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, tsc->tsmhandler);
 		add_object_address(ProcedureRelationId, tsc->tsmhandler, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -2354,9 +2563,12 @@ process_function_rte_ref(RangeTblEntry *rte, AttrNumber attnum,
 
 				Assert(attnum - atts_done <= tupdesc->natts);
 				if (OidIsValid(reltype))	/* can this fail? */
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
 					add_object_address(RelationRelationId, reltype,
 									   attnum - atts_done,
 									   context->addrs);
+				}
 				return;
 			}
 			/* Nothing to do; function's result type is handled elsewhere */
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index 0078a12f26..e92c8363e0 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -844,6 +844,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		/* Add dependency info */
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId, attr->atttypid);
+		LockNotPinnedObject(TypeRelationId, attr->atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -852,6 +853,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 attr->attcollation);
+			LockNotPinnedObject(CollationRelationId, attr->attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1459,11 +1461,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1477,6 +1481,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3390,6 +3395,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3397,6 +3403,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index 9162b9f81a..0ede0fd153 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1116,6 +1116,7 @@ index_create(Relation heapRelation,
 		else
 		{
 			bool		have_simple_col = false;
+			bool		locked_object = false;
 
 			addrs = new_object_addresses();
 
@@ -1128,6 +1129,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					if (!locked_object)
+					{
+						LockNotPinnedObject(RelationRelationId, heapRelationId);
+						locked_object = true;
+					}
 					have_simple_col = true;
 				}
 			}
@@ -1143,6 +1150,8 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				LockNotPinnedObject(RelationRelationId, heapRelationId);
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1158,9 +1167,13 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			LockNotPinnedObject(RelationRelationId, parentIndexRelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			LockNotPinnedObject(RelationRelationId, heapRelationId);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1176,6 +1189,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1184,6 +1198,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1993,6 +2008,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -2004,9 +2027,12 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(heapRelation));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 85a7b7e641..17c4085948 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949..a47e3c5507 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d..dcce454f00 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d51..d3707e424c 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f701229..78498b8c20 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 54f3fb50a5..8999c997f9 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -256,17 +256,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (constraintNTotalKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < constraintNTotalKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, relId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			LockNotPinnedObject(RelationRelationId, relId);
 		}
 	}
 
@@ -279,6 +288,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -298,17 +308,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (foreignNKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < foreignNKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, foreignRelId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			LockNotPinnedObject(RelationRelationId, foreignRelId);
 		}
 	}
 
@@ -324,6 +343,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		LockNotPinnedObject(RelationRelationId, indexRelId);
 	}
 
 	if (foreignNKeys > 0)
@@ -343,15 +363,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -863,9 +886,12 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac..25881654d6 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 2b4514e8a3..d9760d7d05 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,19 +20,20 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
 
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
@@ -99,6 +100,37 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		if (!isObjectPinned(referenced))
+		{
+			if (referenced->classId != RelationRelationId)
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag,
+								   MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId,
+								   0);
+				/* assert the referenced object is locked */
+				Assert(LockHeldByMe(&tag, AccessShareLock, false));
+			}
+			else
+			{
+				Assert(!IsSharedRelation(referenced->objectId));
+
+				/*
+				 * Assert the referenced object is locked if it should be
+				 * visible (see the comment related to LockNotPinnedObject()
+				 * in TypeCreate()).
+				 */
+				Assert(!ObjectByIdExist(referenced) ||
+					   CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -238,6 +270,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -705,7 +738,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a..e8374eec88 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f..116e524390 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 7e5e357fd9..35e7425ac6 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -395,6 +395,7 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 				referenced;
 	List	   *relids = NIL;
 	int			i;
+	bool		locked = false;
 
 	rel = table_open(PublicationRelRelationId, RowExclusiveLock);
 
@@ -457,10 +458,13 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	LockNotPinnedObject(RelationRelationId, relid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -474,6 +478,11 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	while ((i = bms_next_member(attnums, i)) >= 0)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, i);
+		if (!locked)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked = true;
+		}
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -643,10 +652,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba410..e5b5a0b6f8 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed8..82ee7bc2e3 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,37 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid not added to pg_class yet (In heap_create_with_catalog(),
+		 * AddNewRelationType() is called before AddNewRelationTuple()).
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +543,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index ad3082c62a..039c824dab 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -383,6 +383,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		LockNotPinnedObject(RelationRelationId, relOid);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb447..57e86f576a 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -807,6 +810,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc..8616a7c9fa 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index ae0863d9a2..f30ba63ee1 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1271,6 +1271,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1279,6 +1280,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1380,6 +1383,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r1);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1388,6 +1393,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r2);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index a586d246ec..5359aaf239 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index ec71761377..6656937126 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -2031,6 +2031,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -2039,6 +2040,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -3075,6 +3077,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3365,6 +3368,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3521,6 +3525,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1f..735bca486c 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index d43b89d3ef..4b0c203acb 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1446,6 +1446,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1459,6 +1460,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1975,21 +1977,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 2f652463e3..2799742826 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4517,8 +4517,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			LockNotPinnedObject(RelationRelationId, parentOid);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			LockNotPinnedObject(RelationRelationId, partitionIdx->rd_index->indrelid);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5..e70afd216c 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 5872a3e192..58a69e7cc2 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba824..9da98cbeec 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017e..fadfd9064f 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index 0188e8bbd5..d7ba2e59e6 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1691,6 +1691,8 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(tablerel));
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d2..9f0b03388a 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -88,6 +88,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	bool		build_mcv;
 	bool		build_expressions;
 	bool		requested_type = false;
+	bool		locked_object = false;
 	int			i;
 	ListCell   *cell;
 	ListCell   *cell2;
@@ -536,6 +537,12 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		if (!locked_object)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked_object = true;
+		}
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +560,8 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +582,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index e14bc0c054..ea775bf531 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3445,6 +3445,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, parentOid);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7367,7 +7368,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10311,11 +10314,16 @@ addFkConstraint(addFkConstraintSides fkside,
 
 		Assert(fkside != addFkBothSides);
 		if (fkside == addFkReferencedSide)
+		{
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
+		}
 		else
 		{
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -13495,7 +13503,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -15058,6 +15068,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -15077,6 +15088,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -16679,6 +16691,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17445,14 +17458,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
 								relOid,
 								NamespaceRelationId,
 								oldNspOid,
 								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	else
 		UnlockTuple(classRel, &classTup->t_self, InplaceUpdateTupleLock);
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 09356e46d1..f1782f0c65 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1019,8 +1019,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1028,6 +1026,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1046,6 +1051,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1059,6 +1065,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1071,6 +1078,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1078,6 +1087,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			LockNotPinnedObject(RelationRelationId, constrrelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1092,6 +1103,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1101,8 +1113,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1111,12 +1126,19 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	if (columns != NULL)
 	{
 		int			i;
+		bool		locked_object = false;
 
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			if (!locked_object)
+			{
+				LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
+				locked_object = true;
+			}
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1256,9 +1278,12 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e..1b90e187ea 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,48 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsstart - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsstart - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prstoken - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prstoken - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsend - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsend - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsheadline - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsheadline - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prslextype - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prslextype - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +495,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -723,6 +748,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +759,23 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmplinit - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmplinit - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmpllexize - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmpllexize - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -998,6 +1032,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1063,6 +1101,7 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = cfgmap->mapseqno;
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = cfgmap->mapdict;
 
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 			ExecStoreVirtualTuple(slot[slot_stored_count]);
 			slot_stored_count++;
 
@@ -1156,9 +1195,13 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
+	ScanKeyData skey;
+	SysScanDesc scan;
+	HeapTuple	maptup;
 
 	/* Find the configuration */
 	tup = GetTSConfigTuple(stmt->cfgname);
@@ -1168,7 +1211,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1227,28 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+
+	ScanKeyInit(&skey,
+				Anum_pg_ts_config_map_mapcfg,
+				BTEqualStrategyNumber, F_OIDEQ,
+				ObjectIdGetDatum(cfgId));
+
+	scan = systable_beginscan(relMap, TSConfigMapIndexId, true,
+							  NULL, 1, &skey);
+
+	while (HeapTupleIsValid((maptup = systable_getnext(scan))))
+	{
+		Form_pg_ts_config_map cfgmap = (Form_pg_ts_config_map) GETSTRUCT(maptup);
+
+		LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
+	}
+
+	systable_endscan(scan);
+
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1480,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1524,9 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				/* Lock dependent objects */
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a6550de90..25be046308 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2672,6 +2674,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4278,10 +4319,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4573,6 +4617,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4621,6 +4666,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bf..c930eca262 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, eventrel_oid);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 97d91eb1e9..33b0c750e4 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -277,6 +277,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 6908ca7180..0546bcbe16 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,8 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -172,6 +174,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..56f746264b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 143109aa4d..0e80dfecfb 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -115,3 +115,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/modules/test_oat_hooks/expected/alter_table.out b/src/test/modules/test_oat_hooks/expected/alter_table.out
index 8cbacca2c9..df8d276dfc 100644
--- a/src/test/modules/test_oat_hooks/expected/alter_table.out
+++ b/src/test/modules/test_oat_hooks/expected/alter_table.out
@@ -37,6 +37,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE RULE test_oat_notify AS
   ON UPDATE TO test_oat_schema.test_oat_tab
@@ -62,8 +64,6 @@ BEGIN
   END IF;
 END; $$;
 NOTICE:  in process utility: superuser attempting CREATE FUNCTION
-NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
-NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [explicit]
 NOTICE:  in object access: superuser finished create (subId=0x0) [explicit]
 NOTICE:  in process utility: superuser finished CREATE FUNCTION
diff --git a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
index effdc49145..da6d931994 100644
--- a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
+++ b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
@@ -86,6 +86,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE INDEX regress_test_table_t_idx ON regress_test_table (t);
 NOTICE:  in process utility: superuser attempting CREATE INDEX
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 143ae7c09c..a34e238024 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2866,11 +2866,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-01 09:39                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-02 05:56                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-10 07:31                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-08-19 15:35                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-10-28 09:30                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2025-01-02 08:15                                                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-02-04 13:24                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2025-01-02 08:15 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Mon, Oct 28, 2024 at 09:30:19AM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Mon, Aug 19, 2024 at 03:35:14PM +0000, Bertrand Drouvot wrote:
> > Hi,
> > 
> > On Wed, Jul 10, 2024 at 07:31:06AM +0000, Bertrand Drouvot wrote:
> > > So, to sum up:
> > > 
> > > A. Locking is now done exclusively with LockNotPinnedObject(Oid classid, Oid objid)
> > > so that it's now always clear what object we want to acquire a lock for. It means
> > > we are not manipulating directly an object address or a list of objects address
> > > as it was the case when the locking was done "directly" within the dependency code.
> > > 
> > > B. A special case is done for objects that belong to the RelationRelationId class.
> > > For those, we should be in one of the two following cases that would already
> > > prevent the relation to be dropped:
> > > 
> > >  1. The relation is already locked (could be an existing relation or a relation
> > >  that we are creating).
> > > 
> > >  2. The relation is protected indirectly (i.e an index protected by a lock on
> > >  its table, a table protected by a lock on a function that depends the table...)
> > > 
> > > To avoid any risks for the RelationRelationId class case, we acquire a lock if
> > > there is none. That may add unnecessary lock for 2. but that seems worth it. 
> > > 
> > 
> > Please find attached v16, mandatory rebase due to 80ffcb8427.
> 
> rebased (v17 attached).

rebased (v18 attached).

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v18-0001-Avoid-orphaned-objects-dependencies.patch (112.3K, ../../Z3ZLEZsZtKfntQVW@ip-10-97-1-34.eu-west-3.compute.internal/2-v18-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From b2b6810fabd4743fa18bf19d714805e6bb219da5 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v18] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch takes into account any type of objects except the ones that are pinned
(they are not droppable because the system requires it).

A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that's worth it.

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 212 ++++++++++++++++++
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  26 +++
 src/backend/catalog/objectaddress.c           |  57 +++++
 src/backend/catalog/pg_aggregate.c            |   9 +
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  26 +++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  39 +++-
 src/backend/catalog/pg_operator.c             |  19 ++
 src/backend/catalog/pg_proc.c                 |  17 +-
 src/backend/catalog/pg_publication.c          |  11 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  39 ++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   7 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 ++
 src/backend/commands/operatorcmds.c           |  30 +++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   2 +
 src/backend/commands/statscmds.c              |  10 +
 src/backend/commands/tablecmds.c              |  24 +-
 src/backend/commands/trigger.c                |  29 ++-
 src/backend/commands/tsearchcmds.c            |  73 +++++-
 src/backend/commands/typecmds.c               |  84 +++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   3 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 +++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++
 .../test_oat_hooks/expected/alter_table.out   |   4 +-
 .../expected/test_oat_hooks.out               |   2 +
 src/test/regress/expected/alter_table.out     |  11 +-
 46 files changed, 1009 insertions(+), 20 deletions(-)
  40.0% src/backend/catalog/
  29.8% src/backend/commands/
  16.8% src/test/isolation/expected/
  10.5% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index b196294fb2..126a648597 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1341,6 +1341,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 096b68c7f3..5149e28aa0 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,81 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description = NULL;
+
+	if (isObjectPinned(object))
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	if (object->classId == RelationRelationId)
+	{
+		Assert(!IsSharedRelation(object->objectId));
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+	}
+	else
+	{
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1730,6 +1805,7 @@ find_expr_references_walker(Node *node,
 		if (rte->rtekind == RTE_RELATION)
 		{
 			/* If it's a plain relation, reference this column */
+			LockNotPinnedObject(RelationRelationId, rte->relid);
 			add_object_address(RelationRelationId, rte->relid, var->varattno,
 							   context->addrs);
 		}
@@ -1756,6 +1832,7 @@ find_expr_references_walker(Node *node,
 		Oid			objoid;
 
 		/* A constant must depend on the constant's datatype */
+		LockNotPinnedObject(TypeRelationId, con->consttype);
 		add_object_address(TypeRelationId, con->consttype, 0,
 						   context->addrs);
 
@@ -1767,8 +1844,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (OidIsValid(con->constcollid) &&
 			con->constcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, con->constcollid);
 			add_object_address(CollationRelationId, con->constcollid, 0,
 							   context->addrs);
+		}
 
 		/*
 		 * If it's a regclass or similar literal referring to an existing
@@ -1785,59 +1865,83 @@ find_expr_references_walker(Node *node,
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(PROCOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(ProcedureRelationId, objoid);
 						add_object_address(ProcedureRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGOPEROID:
 				case REGOPERATOROID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(OPEROID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(OperatorRelationId, objoid);
 						add_object_address(OperatorRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCLASSOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(RELOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(RelationRelationId, objoid);
 						add_object_address(RelationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGTYPEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TYPEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TypeRelationId, objoid);
 						add_object_address(TypeRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCOLLATIONOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(COLLOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(CollationRelationId, objoid);
 						add_object_address(CollationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCONFIGOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSCONFIGOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSConfigRelationId, objoid);
 						add_object_address(TSConfigRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGDICTIONARYOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSDICTOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSDictionaryRelationId, objoid);
 						add_object_address(TSDictionaryRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 				case REGNAMESPACEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(NAMESPACEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(NamespaceRelationId, objoid);
 						add_object_address(NamespaceRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 					/*
@@ -1859,18 +1963,23 @@ find_expr_references_walker(Node *node,
 		Param	   *param = (Param *) node;
 
 		/* A parameter must depend on the parameter's datatype */
+		LockNotPinnedObject(TypeRelationId, param->paramtype);
 		add_object_address(TypeRelationId, param->paramtype, 0,
 						   context->addrs);
 		/* and its collation, just as for Consts */
 		if (OidIsValid(param->paramcollid) &&
 			param->paramcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, param->paramcollid);
 			add_object_address(CollationRelationId, param->paramcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FuncExpr))
 	{
 		FuncExpr   *funcexpr = (FuncExpr *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, funcexpr->funcid);
 		add_object_address(ProcedureRelationId, funcexpr->funcid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1879,6 +1988,7 @@ find_expr_references_walker(Node *node,
 	{
 		OpExpr	   *opexpr = (OpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1887,6 +1997,7 @@ find_expr_references_walker(Node *node,
 	{
 		DistinctExpr *distinctexpr = (DistinctExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, distinctexpr->opno);
 		add_object_address(OperatorRelationId, distinctexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1895,6 +2006,7 @@ find_expr_references_walker(Node *node,
 	{
 		NullIfExpr *nullifexpr = (NullIfExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, nullifexpr->opno);
 		add_object_address(OperatorRelationId, nullifexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1903,6 +2015,7 @@ find_expr_references_walker(Node *node,
 	{
 		ScalarArrayOpExpr *opexpr = (ScalarArrayOpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1911,6 +2024,7 @@ find_expr_references_walker(Node *node,
 	{
 		Aggref	   *aggref = (Aggref *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, aggref->aggfnoid);
 		add_object_address(ProcedureRelationId, aggref->aggfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1919,6 +2033,7 @@ find_expr_references_walker(Node *node,
 	{
 		WindowFunc *wfunc = (WindowFunc *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, wfunc->winfnoid);
 		add_object_address(ProcedureRelationId, wfunc->winfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1935,8 +2050,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (sbsref->refrestype != sbsref->refcontainertype &&
 			sbsref->refrestype != sbsref->refelemtype)
+		{
+			LockNotPinnedObject(TypeRelationId, sbsref->refrestype);
 			add_object_address(TypeRelationId, sbsref->refrestype, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SubPlan))
@@ -1960,16 +2078,25 @@ find_expr_references_walker(Node *node,
 		 * anywhere else in the expression.
 		 */
 		if (OidIsValid(reltype))
+		{
+			LockNotPinnedObject(RelationRelationId, reltype);
 			add_object_address(RelationRelationId, reltype, fselect->fieldnum,
 							   context->addrs);
+		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fselect->resulttype);
 			add_object_address(TypeRelationId, fselect->resulttype, 0,
 							   context->addrs);
+		}
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(fselect->resultcollid) &&
 			fselect->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, fselect->resultcollid);
 			add_object_address(CollationRelationId, fselect->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FieldStore))
 	{
@@ -1980,53 +2107,76 @@ find_expr_references_walker(Node *node,
 		if (OidIsValid(reltype))
 		{
 			ListCell   *l;
+			bool	locked = false;
 
 			foreach(l, fstore->fieldnums)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
+					locked = true;
+				}
 				add_object_address(RelationRelationId, reltype, lfirst_int(l),
 								   context->addrs);
+			}
 		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fstore->resulttype);
 			add_object_address(TypeRelationId, fstore->resulttype, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, RelabelType))
 	{
 		RelabelType *relab = (RelabelType *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, relab->resulttype);
 		add_object_address(TypeRelationId, relab->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(relab->resultcollid) &&
 			relab->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, relab->resultcollid);
 			add_object_address(CollationRelationId, relab->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, CoerceViaIO))
 	{
 		CoerceViaIO *iocoerce = (CoerceViaIO *) node;
 
 		/* since there is no exposed function, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, iocoerce->resulttype);
 		add_object_address(TypeRelationId, iocoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(iocoerce->resultcollid) &&
 			iocoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, iocoerce->resultcollid);
 			add_object_address(CollationRelationId, iocoerce->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, ArrayCoerceExpr))
 	{
 		ArrayCoerceExpr *acoerce = (ArrayCoerceExpr *) node;
 
 		/* as above, depend on type */
+		LockNotPinnedObject(TypeRelationId, acoerce->resulttype);
 		add_object_address(TypeRelationId, acoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(acoerce->resultcollid) &&
 			acoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, acoerce->resultcollid);
 			add_object_address(CollationRelationId, acoerce->resultcollid, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, ConvertRowtypeExpr))
@@ -2034,6 +2184,7 @@ find_expr_references_walker(Node *node,
 		ConvertRowtypeExpr *cvt = (ConvertRowtypeExpr *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, cvt->resulttype);
 		add_object_address(TypeRelationId, cvt->resulttype, 0,
 						   context->addrs);
 	}
@@ -2041,6 +2192,7 @@ find_expr_references_walker(Node *node,
 	{
 		CollateExpr *coll = (CollateExpr *) node;
 
+		LockNotPinnedObject(CollationRelationId, coll->collOid);
 		add_object_address(CollationRelationId, coll->collOid, 0,
 						   context->addrs);
 	}
@@ -2048,6 +2200,7 @@ find_expr_references_walker(Node *node,
 	{
 		RowExpr    *rowexpr = (RowExpr *) node;
 
+		LockNotPinnedObject(TypeRelationId, rowexpr->row_typeid);
 		add_object_address(TypeRelationId, rowexpr->row_typeid, 0,
 						   context->addrs);
 	}
@@ -2058,11 +2211,13 @@ find_expr_references_walker(Node *node,
 
 		foreach(l, rcexpr->opnos)
 		{
+			LockNotPinnedObject(OperatorRelationId, lfirst_oid(l));
 			add_object_address(OperatorRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
 		foreach(l, rcexpr->opfamilies)
 		{
+			LockNotPinnedObject(OperatorFamilyRelationId, lfirst_oid(l));
 			add_object_address(OperatorFamilyRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
@@ -2072,6 +2227,7 @@ find_expr_references_walker(Node *node,
 	{
 		CoerceToDomain *cd = (CoerceToDomain *) node;
 
+		LockNotPinnedObject(TypeRelationId, cd->resulttype);
 		add_object_address(TypeRelationId, cd->resulttype, 0,
 						   context->addrs);
 	}
@@ -2079,6 +2235,7 @@ find_expr_references_walker(Node *node,
 	{
 		NextValueExpr *nve = (NextValueExpr *) node;
 
+		LockNotPinnedObject(RelationRelationId, nve->seqid);
 		add_object_address(RelationRelationId, nve->seqid, 0,
 						   context->addrs);
 	}
@@ -2087,19 +2244,26 @@ find_expr_references_walker(Node *node,
 		OnConflictExpr *onconflict = (OnConflictExpr *) node;
 
 		if (OidIsValid(onconflict->constraint))
+		{
+			LockNotPinnedObject(ConstraintRelationId, onconflict->constraint);
 			add_object_address(ConstraintRelationId, onconflict->constraint, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SortGroupClause))
 	{
 		SortGroupClause *sgc = (SortGroupClause *) node;
 
+		LockNotPinnedObject(OperatorRelationId, sgc->eqop);
 		add_object_address(OperatorRelationId, sgc->eqop, 0,
 						   context->addrs);
 		if (OidIsValid(sgc->sortop))
+		{
+			LockNotPinnedObject(OperatorRelationId, sgc->sortop);
 			add_object_address(OperatorRelationId, sgc->sortop, 0,
 							   context->addrs);
+		}
 		return false;
 	}
 	else if (IsA(node, WindowClause))
@@ -2107,15 +2271,24 @@ find_expr_references_walker(Node *node,
 		WindowClause *wc = (WindowClause *) node;
 
 		if (OidIsValid(wc->startInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->startInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->startInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->endInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->endInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->endInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->inRangeColl) &&
 			wc->inRangeColl != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, wc->inRangeColl);
 			add_object_address(CollationRelationId, wc->inRangeColl, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, CTECycleClause))
@@ -2123,14 +2296,23 @@ find_expr_references_walker(Node *node,
 		CTECycleClause *cc = (CTECycleClause *) node;
 
 		if (OidIsValid(cc->cycle_mark_type))
+		{
+			LockNotPinnedObject(TypeRelationId, cc->cycle_mark_type);
 			add_object_address(TypeRelationId, cc->cycle_mark_type, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_collation))
+		{
+			LockNotPinnedObject(CollationRelationId, cc->cycle_mark_collation);
 			add_object_address(CollationRelationId, cc->cycle_mark_collation, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_neop))
+		{
+			LockNotPinnedObject(OperatorRelationId, cc->cycle_mark_neop);
 			add_object_address(OperatorRelationId, cc->cycle_mark_neop, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, Query))
@@ -2163,6 +2345,7 @@ find_expr_references_walker(Node *node,
 			switch (rte->rtekind)
 			{
 				case RTE_RELATION:
+					LockNotPinnedObject(RelationRelationId, rte->relid);
 					add_object_address(RelationRelationId, rte->relid, 0,
 									   context->addrs);
 					break;
@@ -2215,12 +2398,18 @@ find_expr_references_walker(Node *node,
 			rte = rt_fetch(query->resultRelation, query->rtable);
 			if (rte->rtekind == RTE_RELATION)
 			{
+				bool	locked = false;
 				foreach(lc, query->targetList)
 				{
 					TargetEntry *tle = (TargetEntry *) lfirst(lc);
 
 					if (tle->resjunk)
 						continue;	/* ignore junk tlist items */
+					if (!locked)
+					{
+						LockNotPinnedObject(RelationRelationId, rte->relid);
+						locked = true;
+					}
 					add_object_address(RelationRelationId, rte->relid, tle->resno,
 									   context->addrs);
 				}
@@ -2232,6 +2421,7 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(lc, query->constraintDeps)
 		{
+			LockNotPinnedObject(ConstraintRelationId, lfirst_oid(lc));
 			add_object_address(ConstraintRelationId, lfirst_oid(lc), 0,
 							   context->addrs);
 		}
@@ -2266,16 +2456,25 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, rtfunc->funccoltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, rtfunc->funccolcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool	locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableFunc))
@@ -2288,22 +2487,32 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, tf->coltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, tf->colcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool 	locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableSampleClause))
 	{
 		TableSampleClause *tsc = (TableSampleClause *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, tsc->tsmhandler);
 		add_object_address(ProcedureRelationId, tsc->tsmhandler, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -2354,9 +2563,12 @@ process_function_rte_ref(RangeTblEntry *rte, AttrNumber attnum,
 
 				Assert(attnum - atts_done <= tupdesc->natts);
 				if (OidIsValid(reltype))	/* can this fail? */
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
 					add_object_address(RelationRelationId, reltype,
 									   attnum - atts_done,
 									   context->addrs);
+				}
 				return;
 			}
 			/* Nothing to do; function's result type is handled elsewhere */
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index 4d760c98d1..f333a91cfe 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -836,6 +836,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		/* Add dependency info */
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId, attr->atttypid);
+		LockNotPinnedObject(TypeRelationId, attr->atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -844,6 +845,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 attr->attcollation);
+			LockNotPinnedObject(CollationRelationId, attr->attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1451,11 +1453,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1471,6 +1475,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3771,6 +3776,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3778,6 +3784,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index 221fbb4e28..1e5859ad4b 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1117,6 +1117,7 @@ index_create(Relation heapRelation,
 		else
 		{
 			bool		have_simple_col = false;
+			bool		locked_object = false;
 
 			addrs = new_object_addresses();
 
@@ -1129,6 +1130,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					if (!locked_object)
+					{
+						LockNotPinnedObject(RelationRelationId, heapRelationId);
+						locked_object = true;
+					}
 					have_simple_col = true;
 				}
 			}
@@ -1144,6 +1151,8 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				LockNotPinnedObject(RelationRelationId, heapRelationId);
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1159,9 +1168,13 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			LockNotPinnedObject(RelationRelationId, parentIndexRelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			LockNotPinnedObject(RelationRelationId, heapRelationId);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1177,6 +1190,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1185,6 +1199,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1994,6 +2009,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -2005,9 +2028,12 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(heapRelation));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index d8eb8d3dea..f3e82671df 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2595,6 +2595,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index bcf4050f5b..ce5865fac6 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 91dafc8102..91da30c504 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 1773c9c549..90513a39ac 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 469635b358..fa6fd7bf79 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 0c6ac0be41..cee0bdc280 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -257,17 +257,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (constraintNTotalKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < constraintNTotalKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, relId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			LockNotPinnedObject(RelationRelationId, relId);
 		}
 	}
 
@@ -280,6 +289,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -299,17 +309,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (foreignNKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < foreignNKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, foreignRelId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			LockNotPinnedObject(RelationRelationId, foreignRelId);
 		}
 	}
 
@@ -325,6 +344,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		LockNotPinnedObject(RelationRelationId, indexRelId);
 	}
 
 	if (foreignNKeys > 0)
@@ -344,15 +364,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -1110,9 +1133,12 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 04cc375cae..5ac365ebd0 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index c8b11f887e..fdafffb893 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,19 +20,20 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
 
 /*
  * Record a dependency between 2 objects via their respective ObjectAddress.
@@ -99,6 +100,37 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		if (!isObjectPinned(referenced))
+		{
+			if (referenced->classId != RelationRelationId)
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag,
+								   MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId,
+								   0);
+				/* assert the referenced object is locked */
+				Assert(LockHeldByMe(&tag, AccessShareLock, false));
+			}
+			else
+			{
+				Assert(!IsSharedRelation(referenced->objectId));
+
+				/*
+				 * Assert the referenced object is locked if it should be
+				 * visible (see the comment related to LockNotPinnedObject()
+				 * in TypeCreate()).
+				 */
+				Assert(!ObjectByIdExist(referenced) ||
+					   CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -238,6 +270,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -705,7 +738,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index bfcfa64346..ba6aa33218 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index fe0490259e..c3999bdce8 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index b89098f5e9..2d44b8b0e5 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -441,6 +441,7 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 				referenced;
 	List	   *relids = NIL;
 	int			i;
+	bool		locked = false;
 
 	rel = table_open(PublicationRelRelationId, RowExclusiveLock);
 
@@ -503,10 +504,13 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	LockNotPinnedObject(RelationRelationId, relid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -520,6 +524,11 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	while ((i = bms_next_member(attnums, i)) >= 0)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, i);
+		if (!locked)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked = true;
+		}
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -705,10 +714,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 8df73e7ab7..e1538c2146 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index b36f81afb9..77ff5f0603 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,37 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid not added to pg_class yet (In heap_create_with_catalog(),
+		 * AddNewRelationType() is called before AddNewRelationTuple()).
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +543,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 874a8fc89a..b8fb22af6a 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -383,6 +383,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		LockNotPinnedObject(RelationRelationId, relOid);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 78c1d4e1b8..e068b127c2 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -499,7 +499,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -803,6 +806,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index 58ed9d216c..eb9b86d563 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index effd395086..60b18f9f7c 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1271,6 +1271,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1279,6 +1280,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1380,6 +1383,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r1);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1388,6 +1393,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r2);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index edc2c988e2..14dab63ef0 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index ba540e3de5..01813ac71d 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -2035,6 +2035,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -2043,6 +2044,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -3079,6 +3081,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3369,6 +3372,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3525,6 +3529,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index c14e038d54..d6cced22e7 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index b9fd7683ab..e215551147 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1461,6 +1461,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1474,6 +1475,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1990,21 +1992,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index d6e23caef1..ef828df294 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4524,8 +4524,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			LockNotPinnedObject(RelationRelationId, parentOid);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			LockNotPinnedObject(RelationRelationId, partitionIdx->rd_index->indrelid);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index 2c325badf9..72b347e980 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -299,12 +299,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -726,18 +728,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -746,6 +751,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1487,6 +1493,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1497,6 +1510,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1505,6 +1519,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1538,6 +1553,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1621,6 +1637,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1629,6 +1646,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 673648f1fc..59a4715fff 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 83056960fe..cf5e194792 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 5036ac0363..f4a7e46b71 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index b13ee2b745..31dba914b8 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1691,6 +1691,8 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(tablerel));
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index a817821bf6..5b7950d582 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -88,6 +88,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	bool		build_mcv;
 	bool		build_expressions;
 	bool		requested_type = false;
+	bool		locked_object = false;
 	int			i;
 	ListCell   *cell;
 	ListCell   *cell2;
@@ -536,6 +537,12 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		if (!locked_object)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked_object = true;
+		}
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +560,8 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +582,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 33ea619224..4797ac5463 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3499,6 +3499,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, parentOid);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7401,7 +7402,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10481,11 +10484,16 @@ addFkConstraint(addFkConstraintSides fkside,
 
 		Assert(fkside != addFkBothSides);
 		if (fkside == addFkReferencedSide)
+		{
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
+		}
 		else
 		{
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -13791,7 +13799,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -15369,6 +15379,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -15388,6 +15399,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -17095,6 +17107,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17867,14 +17880,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
 								relOid,
 								NamespaceRelationId,
 								oldNspOid,
 								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	else
 		UnlockTuple(classRel, &classTup->t_self, InplaceUpdateTupleLock);
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 32f25f4d91..a4db8a8f67 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1019,8 +1019,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1028,6 +1026,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1046,6 +1051,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1059,6 +1065,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1071,6 +1078,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1078,6 +1087,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			LockNotPinnedObject(RelationRelationId, constrrelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1092,6 +1103,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1101,8 +1113,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1111,12 +1126,19 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	if (columns != NULL)
 	{
 		int			i;
+		bool		locked_object = false;
 
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			if (!locked_object)
+			{
+				LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
+				locked_object = true;
+			}
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1256,9 +1278,12 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index ab16d42ad5..e36c3da102 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,48 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsstart - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsstart - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prstoken - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prstoken - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsend - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsend - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsheadline - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsheadline - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prslextype - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prslextype - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +495,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -723,6 +748,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +759,23 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmplinit - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmplinit - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmpllexize - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmpllexize - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -998,6 +1032,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1063,6 +1101,7 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = cfgmap->mapseqno;
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = cfgmap->mapdict;
 
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 			ExecStoreVirtualTuple(slot[slot_stored_count]);
 			slot_stored_count++;
 
@@ -1156,9 +1195,13 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
+	ScanKeyData skey;
+	SysScanDesc scan;
+	HeapTuple	maptup;
 
 	/* Find the configuration */
 	tup = GetTSConfigTuple(stmt->cfgname);
@@ -1168,7 +1211,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1227,28 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+
+	ScanKeyInit(&skey,
+				Anum_pg_ts_config_map_mapcfg,
+				BTEqualStrategyNumber, F_OIDEQ,
+				ObjectIdGetDatum(cfgId));
+
+	scan = systable_beginscan(relMap, TSConfigMapIndexId, true,
+							  NULL, 1, &skey);
+
+	while (HeapTupleIsValid((maptup = systable_getnext(scan))))
+	{
+		Form_pg_ts_config_map cfgmap = (Form_pg_ts_config_map) GETSTRUCT(maptup);
+
+		LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
+	}
+
+	systable_endscan(scan);
+
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1480,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1524,9 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				/* Lock dependent objects */
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 6b1d238351..2059df09fd 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1812,6 +1812,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1877,6 +1878,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2690,6 +2692,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4296,10 +4337,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4591,6 +4635,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4639,6 +4684,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 8aa90b0d6f..14a6468efc 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, eventrel_oid);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index c96aa7c49e..c664ae4977 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -277,6 +277,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 0ea7ccf524..73ee2c6a78 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,8 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -172,6 +174,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 630434b73c..34d5428433 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 143109aa4d..0e80dfecfb 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -115,3 +115,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/modules/test_oat_hooks/expected/alter_table.out b/src/test/modules/test_oat_hooks/expected/alter_table.out
index 8cbacca2c9..df8d276dfc 100644
--- a/src/test/modules/test_oat_hooks/expected/alter_table.out
+++ b/src/test/modules/test_oat_hooks/expected/alter_table.out
@@ -37,6 +37,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE RULE test_oat_notify AS
   ON UPDATE TO test_oat_schema.test_oat_tab
@@ -62,8 +64,6 @@ BEGIN
   END IF;
 END; $$;
 NOTICE:  in process utility: superuser attempting CREATE FUNCTION
-NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
-NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [explicit]
 NOTICE:  in object access: superuser finished create (subId=0x0) [explicit]
 NOTICE:  in process utility: superuser finished CREATE FUNCTION
diff --git a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
index effdc49145..da6d931994 100644
--- a/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
+++ b/src/test/modules/test_oat_hooks/expected/test_oat_hooks.out
@@ -86,6 +86,8 @@ NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
 NOTICE:  in object access: superuser attempting create (subId=0x0) [internal]
 NOTICE:  in object access: superuser finished create (subId=0x0) [internal]
+NOTICE:  in object access: superuser attempting namespace search (subId=0x0) [no report on violation, allowed]
+NOTICE:  in object access: superuser finished namespace search (subId=0x0) [no report on violation, allowed]
 NOTICE:  in process utility: superuser finished CREATE TABLE
 CREATE INDEX regress_test_table_t_idx ON regress_test_table (t);
 NOTICE:  in process utility: superuser attempting CREATE INDEX
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 12852aa612..552edf57b9 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2852,11 +2852,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-01 09:39                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-02 05:56                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-10 07:31                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-08-19 15:35                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-10-28 09:30                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-01-02 08:15                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2025-02-04 13:24                                                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-23 04:20                                                                               ` Re: Avoid orphaned objects dependencies, take 3 jian he <jian.universality@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2025-02-04 13:24 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jan 02, 2025 at 08:15:13AM +0000, Bertrand Drouvot wrote:
> rebased (v18 attached).

Thanks to all of you that have discussed this patch during the developer meeting
at FOSDEM PGDay last week [1]. I'm attaching a new version to address Álvaro's
concern about calling getObjectDescription() in the new LockNotPinnedObjectById()
function. This call was being used to provide a "meaningful" error message but
we agreed to provide the object OID instead (as anyway the object is dropped).

Note that the OIDs are reported as "errdetail" to ensure the isolation tests
added in this patch remain stable (output does not depend of the actual OIDs
values).

A quick sum up about this patch:

A. Locking is done exclusively with LockNotPinnedObject(Oid classid, Oid objid)
so that it's now always clear what object we want to acquire a lock for. It means
that we are not manipulating directly an object address or a list of objects
address as it was the case when the locking was done "directly" within the
dependency code.

B. A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

 B1. The relation is already locked (could be an existing relation or a relation
 that we are creating).

 B2. The relation is protected indirectly (i.e an index protected by a lock on
 its table, a table protected by a lock on a function that depends the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for B2. but that seems worth it. 

That's a lot of mechanical changes so that's easy to miss one or to do it
wrong but:

1. I did my best to avoid that
2. assertions are added in recordMultipleDependencies() to "ensure" the object
is locked
3. even if one case is missing (that is not catched by the assertions because 
the dependency is not covered in the tests, not sure that exists though), then it
just means that we could be in the current state (orphaned dependency), not worst
than that

During the meeting a question has been raised regarding the number of locks
increase. This has already been discussed in [2] and I think that the outcome
is that the default max_locks_per_transaction value (64) is probably still
enough in real life (and even if it is not then it can be increased to satisfy
the requirements).

[1]: https://2025.fosdempgday.org/devmeeting
[2]: https://www.postgresql.org/message-id/CA%2BTgmoaFPUubBBk52Qp2wkoL7JX7OjhewiK%2B7LSot7%3DrecbzzQ%40ma...

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v19-0001-Avoid-orphaned-objects-dependencies.patch (109.5K, ../../Z6IU8+oozjqIHcNV@ip-10-97-1-34.eu-west-3.compute.internal/2-v19-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 78e5dcbb51d7706c0d7b2c896bdaea1a23a7c0e9 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v19] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

The patch takes into account any type of objects except the ones that are pinned
(they are not droppable because the system requires it).

A special case is done for objects that belong to the RelationRelationId class.
For those, we should be in one of the two following cases that would already
prevent the relation to be dropped:

1. The relation is already locked (could be an existing relation or a relation
that we are creating).

2. The relation is protected indirectly (i.e an index protected by a lock on
its table, a table protected by a lock on a function that depends of the table...)

To avoid any risks for the RelationRelationId class case, we acquire a lock if
there is none. That may add unnecessary lock for 2. but that's worth it.

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 201 ++++++++++++++++++
 src/backend/catalog/heap.c                    |   7 +
 src/backend/catalog/index.c                   |  26 +++
 src/backend/catalog/objectaddress.c           |  57 +++++
 src/backend/catalog/pg_aggregate.c            |   9 +
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  26 +++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  39 +++-
 src/backend/catalog/pg_operator.c             |  19 ++
 src/backend/catalog/pg_proc.c                 |  17 +-
 src/backend/catalog/pg_publication.c          |  11 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  39 ++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   7 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 ++
 src/backend/commands/operatorcmds.c           |  30 +++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   2 +
 src/backend/commands/statscmds.c              |  10 +
 src/backend/commands/tablecmds.c              |  32 ++-
 src/backend/commands/trigger.c                |  29 ++-
 src/backend/commands/tsearchcmds.c            |  73 ++++++-
 src/backend/commands/typecmds.c               |  84 ++++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   3 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 +++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++
 src/test/regress/expected/alter_table.out     |  11 +-
 44 files changed, 998 insertions(+), 22 deletions(-)
  39.7% src/backend/catalog/
  30.5% src/backend/commands/
  17.0% src/test/isolation/expected/
  10.5% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 02a754cc30a..420641633c5 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1341,6 +1341,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 18316a3968b..34884aa8950 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,69 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	if (isObjectPinned(object))
+		return;
+
+	if (object->classId == RelationRelationId)
+	{
+		Assert(!IsSharedRelation(object->objectId));
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+	}
+	else
+	{
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+		ereport(ERROR,
+				(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+				 errmsg("dependent object does not exist"),
+				 errdetail("Class OID is %u and object OID is %u",
+						   object->classId, object->objectId)));
+
+	return;
+}
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1730,6 +1793,7 @@ find_expr_references_walker(Node *node,
 		if (rte->rtekind == RTE_RELATION)
 		{
 			/* If it's a plain relation, reference this column */
+			LockNotPinnedObject(RelationRelationId, rte->relid);
 			add_object_address(RelationRelationId, rte->relid, var->varattno,
 							   context->addrs);
 		}
@@ -1756,6 +1820,7 @@ find_expr_references_walker(Node *node,
 		Oid			objoid;
 
 		/* A constant must depend on the constant's datatype */
+		LockNotPinnedObject(TypeRelationId, con->consttype);
 		add_object_address(TypeRelationId, con->consttype, 0,
 						   context->addrs);
 
@@ -1767,8 +1832,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (OidIsValid(con->constcollid) &&
 			con->constcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, con->constcollid);
 			add_object_address(CollationRelationId, con->constcollid, 0,
 							   context->addrs);
+		}
 
 		/*
 		 * If it's a regclass or similar literal referring to an existing
@@ -1785,59 +1853,83 @@ find_expr_references_walker(Node *node,
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(PROCOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(ProcedureRelationId, objoid);
 						add_object_address(ProcedureRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGOPEROID:
 				case REGOPERATOROID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(OPEROID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(OperatorRelationId, objoid);
 						add_object_address(OperatorRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCLASSOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(RELOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(RelationRelationId, objoid);
 						add_object_address(RelationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGTYPEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TYPEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TypeRelationId, objoid);
 						add_object_address(TypeRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCOLLATIONOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(COLLOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(CollationRelationId, objoid);
 						add_object_address(CollationRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGCONFIGOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSCONFIGOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSConfigRelationId, objoid);
 						add_object_address(TSConfigRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGDICTIONARYOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(TSDICTOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(TSDictionaryRelationId, objoid);
 						add_object_address(TSDictionaryRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 				case REGNAMESPACEOID:
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(NAMESPACEOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObject(NamespaceRelationId, objoid);
 						add_object_address(NamespaceRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 
 					/*
@@ -1859,18 +1951,23 @@ find_expr_references_walker(Node *node,
 		Param	   *param = (Param *) node;
 
 		/* A parameter must depend on the parameter's datatype */
+		LockNotPinnedObject(TypeRelationId, param->paramtype);
 		add_object_address(TypeRelationId, param->paramtype, 0,
 						   context->addrs);
 		/* and its collation, just as for Consts */
 		if (OidIsValid(param->paramcollid) &&
 			param->paramcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, param->paramcollid);
 			add_object_address(CollationRelationId, param->paramcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FuncExpr))
 	{
 		FuncExpr   *funcexpr = (FuncExpr *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, funcexpr->funcid);
 		add_object_address(ProcedureRelationId, funcexpr->funcid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1879,6 +1976,7 @@ find_expr_references_walker(Node *node,
 	{
 		OpExpr	   *opexpr = (OpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1887,6 +1985,7 @@ find_expr_references_walker(Node *node,
 	{
 		DistinctExpr *distinctexpr = (DistinctExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, distinctexpr->opno);
 		add_object_address(OperatorRelationId, distinctexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1895,6 +1994,7 @@ find_expr_references_walker(Node *node,
 	{
 		NullIfExpr *nullifexpr = (NullIfExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, nullifexpr->opno);
 		add_object_address(OperatorRelationId, nullifexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1903,6 +2003,7 @@ find_expr_references_walker(Node *node,
 	{
 		ScalarArrayOpExpr *opexpr = (ScalarArrayOpExpr *) node;
 
+		LockNotPinnedObject(OperatorRelationId, opexpr->opno);
 		add_object_address(OperatorRelationId, opexpr->opno, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1911,6 +2012,7 @@ find_expr_references_walker(Node *node,
 	{
 		Aggref	   *aggref = (Aggref *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, aggref->aggfnoid);
 		add_object_address(ProcedureRelationId, aggref->aggfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1919,6 +2021,7 @@ find_expr_references_walker(Node *node,
 	{
 		WindowFunc *wfunc = (WindowFunc *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, wfunc->winfnoid);
 		add_object_address(ProcedureRelationId, wfunc->winfnoid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -1935,8 +2038,11 @@ find_expr_references_walker(Node *node,
 		 */
 		if (sbsref->refrestype != sbsref->refcontainertype &&
 			sbsref->refrestype != sbsref->refelemtype)
+		{
+			LockNotPinnedObject(TypeRelationId, sbsref->refrestype);
 			add_object_address(TypeRelationId, sbsref->refrestype, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SubPlan))
@@ -1960,16 +2066,25 @@ find_expr_references_walker(Node *node,
 		 * anywhere else in the expression.
 		 */
 		if (OidIsValid(reltype))
+		{
+			LockNotPinnedObject(RelationRelationId, reltype);
 			add_object_address(RelationRelationId, reltype, fselect->fieldnum,
 							   context->addrs);
+		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fselect->resulttype);
 			add_object_address(TypeRelationId, fselect->resulttype, 0,
 							   context->addrs);
+		}
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(fselect->resultcollid) &&
 			fselect->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, fselect->resultcollid);
 			add_object_address(CollationRelationId, fselect->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, FieldStore))
 	{
@@ -1980,53 +2095,76 @@ find_expr_references_walker(Node *node,
 		if (OidIsValid(reltype))
 		{
 			ListCell   *l;
+			bool		locked = false;
 
 			foreach(l, fstore->fieldnums)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
+					locked = true;
+				}
 				add_object_address(RelationRelationId, reltype, lfirst_int(l),
 								   context->addrs);
+			}
 		}
 		else
+		{
+			LockNotPinnedObject(TypeRelationId, fstore->resulttype);
 			add_object_address(TypeRelationId, fstore->resulttype, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, RelabelType))
 	{
 		RelabelType *relab = (RelabelType *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, relab->resulttype);
 		add_object_address(TypeRelationId, relab->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(relab->resultcollid) &&
 			relab->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, relab->resultcollid);
 			add_object_address(CollationRelationId, relab->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, CoerceViaIO))
 	{
 		CoerceViaIO *iocoerce = (CoerceViaIO *) node;
 
 		/* since there is no exposed function, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, iocoerce->resulttype);
 		add_object_address(TypeRelationId, iocoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(iocoerce->resultcollid) &&
 			iocoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, iocoerce->resultcollid);
 			add_object_address(CollationRelationId, iocoerce->resultcollid, 0,
 							   context->addrs);
+		}
 	}
 	else if (IsA(node, ArrayCoerceExpr))
 	{
 		ArrayCoerceExpr *acoerce = (ArrayCoerceExpr *) node;
 
 		/* as above, depend on type */
+		LockNotPinnedObject(TypeRelationId, acoerce->resulttype);
 		add_object_address(TypeRelationId, acoerce->resulttype, 0,
 						   context->addrs);
 		/* the collation might not be referenced anywhere else, either */
 		if (OidIsValid(acoerce->resultcollid) &&
 			acoerce->resultcollid != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, acoerce->resultcollid);
 			add_object_address(CollationRelationId, acoerce->resultcollid, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, ConvertRowtypeExpr))
@@ -2034,6 +2172,7 @@ find_expr_references_walker(Node *node,
 		ConvertRowtypeExpr *cvt = (ConvertRowtypeExpr *) node;
 
 		/* since there is no function dependency, need to depend on type */
+		LockNotPinnedObject(TypeRelationId, cvt->resulttype);
 		add_object_address(TypeRelationId, cvt->resulttype, 0,
 						   context->addrs);
 	}
@@ -2041,6 +2180,7 @@ find_expr_references_walker(Node *node,
 	{
 		CollateExpr *coll = (CollateExpr *) node;
 
+		LockNotPinnedObject(CollationRelationId, coll->collOid);
 		add_object_address(CollationRelationId, coll->collOid, 0,
 						   context->addrs);
 	}
@@ -2048,6 +2188,7 @@ find_expr_references_walker(Node *node,
 	{
 		RowExpr    *rowexpr = (RowExpr *) node;
 
+		LockNotPinnedObject(TypeRelationId, rowexpr->row_typeid);
 		add_object_address(TypeRelationId, rowexpr->row_typeid, 0,
 						   context->addrs);
 	}
@@ -2058,11 +2199,13 @@ find_expr_references_walker(Node *node,
 
 		foreach(l, rcexpr->opnos)
 		{
+			LockNotPinnedObject(OperatorRelationId, lfirst_oid(l));
 			add_object_address(OperatorRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
 		foreach(l, rcexpr->opfamilies)
 		{
+			LockNotPinnedObject(OperatorFamilyRelationId, lfirst_oid(l));
 			add_object_address(OperatorFamilyRelationId, lfirst_oid(l), 0,
 							   context->addrs);
 		}
@@ -2072,6 +2215,7 @@ find_expr_references_walker(Node *node,
 	{
 		CoerceToDomain *cd = (CoerceToDomain *) node;
 
+		LockNotPinnedObject(TypeRelationId, cd->resulttype);
 		add_object_address(TypeRelationId, cd->resulttype, 0,
 						   context->addrs);
 	}
@@ -2079,6 +2223,7 @@ find_expr_references_walker(Node *node,
 	{
 		NextValueExpr *nve = (NextValueExpr *) node;
 
+		LockNotPinnedObject(RelationRelationId, nve->seqid);
 		add_object_address(RelationRelationId, nve->seqid, 0,
 						   context->addrs);
 	}
@@ -2087,19 +2232,26 @@ find_expr_references_walker(Node *node,
 		OnConflictExpr *onconflict = (OnConflictExpr *) node;
 
 		if (OidIsValid(onconflict->constraint))
+		{
+			LockNotPinnedObject(ConstraintRelationId, onconflict->constraint);
 			add_object_address(ConstraintRelationId, onconflict->constraint, 0,
 							   context->addrs);
+		}
 		/* fall through to examine arguments */
 	}
 	else if (IsA(node, SortGroupClause))
 	{
 		SortGroupClause *sgc = (SortGroupClause *) node;
 
+		LockNotPinnedObject(OperatorRelationId, sgc->eqop);
 		add_object_address(OperatorRelationId, sgc->eqop, 0,
 						   context->addrs);
 		if (OidIsValid(sgc->sortop))
+		{
+			LockNotPinnedObject(OperatorRelationId, sgc->sortop);
 			add_object_address(OperatorRelationId, sgc->sortop, 0,
 							   context->addrs);
+		}
 		return false;
 	}
 	else if (IsA(node, WindowClause))
@@ -2107,15 +2259,24 @@ find_expr_references_walker(Node *node,
 		WindowClause *wc = (WindowClause *) node;
 
 		if (OidIsValid(wc->startInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->startInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->startInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->endInRangeFunc))
+		{
+			LockNotPinnedObject(ProcedureRelationId, wc->endInRangeFunc);
 			add_object_address(ProcedureRelationId, wc->endInRangeFunc, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(wc->inRangeColl) &&
 			wc->inRangeColl != DEFAULT_COLLATION_OID)
+		{
+			LockNotPinnedObject(CollationRelationId, wc->inRangeColl);
 			add_object_address(CollationRelationId, wc->inRangeColl, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, CTECycleClause))
@@ -2123,14 +2284,23 @@ find_expr_references_walker(Node *node,
 		CTECycleClause *cc = (CTECycleClause *) node;
 
 		if (OidIsValid(cc->cycle_mark_type))
+		{
+			LockNotPinnedObject(TypeRelationId, cc->cycle_mark_type);
 			add_object_address(TypeRelationId, cc->cycle_mark_type, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_collation))
+		{
+			LockNotPinnedObject(CollationRelationId, cc->cycle_mark_collation);
 			add_object_address(CollationRelationId, cc->cycle_mark_collation, 0,
 							   context->addrs);
+		}
 		if (OidIsValid(cc->cycle_mark_neop))
+		{
+			LockNotPinnedObject(OperatorRelationId, cc->cycle_mark_neop);
 			add_object_address(OperatorRelationId, cc->cycle_mark_neop, 0,
 							   context->addrs);
+		}
 		/* fall through to examine substructure */
 	}
 	else if (IsA(node, Query))
@@ -2163,6 +2333,7 @@ find_expr_references_walker(Node *node,
 			switch (rte->rtekind)
 			{
 				case RTE_RELATION:
+					LockNotPinnedObject(RelationRelationId, rte->relid);
 					add_object_address(RelationRelationId, rte->relid, 0,
 									   context->addrs);
 					break;
@@ -2230,12 +2401,19 @@ find_expr_references_walker(Node *node,
 			rte = rt_fetch(query->resultRelation, query->rtable);
 			if (rte->rtekind == RTE_RELATION)
 			{
+				bool		locked = false;
+
 				foreach(lc, query->targetList)
 				{
 					TargetEntry *tle = (TargetEntry *) lfirst(lc);
 
 					if (tle->resjunk)
 						continue;	/* ignore junk tlist items */
+					if (!locked)
+					{
+						LockNotPinnedObject(RelationRelationId, rte->relid);
+						locked = true;
+					}
 					add_object_address(RelationRelationId, rte->relid, tle->resno,
 									   context->addrs);
 				}
@@ -2247,6 +2425,7 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(lc, query->constraintDeps)
 		{
+			LockNotPinnedObject(ConstraintRelationId, lfirst_oid(lc));
 			add_object_address(ConstraintRelationId, lfirst_oid(lc), 0,
 							   context->addrs);
 		}
@@ -2281,16 +2460,25 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, rtfunc->funccoltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, rtfunc->funccolcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool		locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableFunc))
@@ -2303,22 +2491,32 @@ find_expr_references_walker(Node *node,
 		 */
 		foreach(ct, tf->coltypes)
 		{
+			LockNotPinnedObject(TypeRelationId, lfirst_oid(ct));
 			add_object_address(TypeRelationId, lfirst_oid(ct), 0,
 							   context->addrs);
 		}
 		foreach(ct, tf->colcollations)
 		{
 			Oid			collid = lfirst_oid(ct);
+			bool		locked = false;
 
 			if (OidIsValid(collid) && collid != DEFAULT_COLLATION_OID)
+			{
+				if (!locked)
+				{
+					LockNotPinnedObject(CollationRelationId, collid);
+					locked = true;
+				}
 				add_object_address(CollationRelationId, collid, 0,
 								   context->addrs);
+			}
 		}
 	}
 	else if (IsA(node, TableSampleClause))
 	{
 		TableSampleClause *tsc = (TableSampleClause *) node;
 
+		LockNotPinnedObject(ProcedureRelationId, tsc->tsmhandler);
 		add_object_address(ProcedureRelationId, tsc->tsmhandler, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
@@ -2369,9 +2567,12 @@ process_function_rte_ref(RangeTblEntry *rte, AttrNumber attnum,
 
 				Assert(attnum - atts_done <= tupdesc->natts);
 				if (OidIsValid(reltype))	/* can this fail? */
+				{
+					LockNotPinnedObject(RelationRelationId, reltype);
 					add_object_address(RelationRelationId, reltype,
 									   attnum - atts_done,
 									   context->addrs);
+				}
 				return;
 			}
 			/* Nothing to do; function's result type is handled elsewhere */
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index 57ef466acce..aaf6949a226 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -837,6 +837,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		/* Add dependency info */
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId, attr->atttypid);
+		LockNotPinnedObject(TypeRelationId, attr->atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -845,6 +846,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 attr->attcollation);
+			LockNotPinnedObject(CollationRelationId, attr->attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1452,11 +1454,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1472,6 +1476,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3799,6 +3804,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3806,6 +3812,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index 7377912b41e..cf442e7f21f 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1117,6 +1117,7 @@ index_create(Relation heapRelation,
 		else
 		{
 			bool		have_simple_col = false;
+			bool		locked_object = false;
 
 			addrs = new_object_addresses();
 
@@ -1129,6 +1130,12 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+
+					if (!locked_object)
+					{
+						LockNotPinnedObject(RelationRelationId, heapRelationId);
+						locked_object = true;
+					}
 					have_simple_col = true;
 				}
 			}
@@ -1144,6 +1151,8 @@ index_create(Relation heapRelation,
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
 				add_exact_object_address(&referenced, addrs);
+
+				LockNotPinnedObject(RelationRelationId, heapRelationId);
 			}
 
 			record_object_address_dependencies(&myself, addrs, DEPENDENCY_AUTO);
@@ -1159,9 +1168,13 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+
+			LockNotPinnedObject(RelationRelationId, parentIndexRelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+
+			LockNotPinnedObject(RelationRelationId, heapRelationId);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1177,6 +1190,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1185,6 +1199,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1995,6 +2010,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement() here to ensure the new constraint entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -2006,9 +2029,12 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(heapRelation));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index d8eb8d3deaa..f3e82671df5 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2595,6 +2595,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index bcf4050f5b1..ce5865fac69 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 91dafc81021..91da30c504e 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 1773c9c5491..90513a39ac6 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 469635b3580..fa6fd7bf791 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index ac80652baf2..79b2df100e6 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -264,17 +264,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (constraintNTotalKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < constraintNTotalKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, relId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			LockNotPinnedObject(RelationRelationId, relId);
 		}
 	}
 
@@ -287,6 +296,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -306,17 +316,26 @@ CreateConstraintEntry(const char *constraintName,
 
 		if (foreignNKeys > 0)
 		{
+			bool		locked_object = false;
+
 			for (i = 0; i < foreignNKeys; i++)
 			{
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+
+				if (!locked_object)
+				{
+					LockNotPinnedObject(RelationRelationId, foreignRelId);
+					locked_object = true;
+				}
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			LockNotPinnedObject(RelationRelationId, foreignRelId);
 		}
 	}
 
@@ -332,6 +351,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		LockNotPinnedObject(RelationRelationId, indexRelId);
 	}
 
 	if (foreignNKeys > 0)
@@ -351,15 +371,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -1119,9 +1142,12 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 04cc375caea..5ac365ebd04 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index c8b11f887e2..fdafffb8934 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,19 +20,20 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
 
 /*
  * Record a dependency between 2 objects via their respective ObjectAddress.
@@ -99,6 +100,37 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		if (!isObjectPinned(referenced))
+		{
+			if (referenced->classId != RelationRelationId)
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag,
+								   MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId,
+								   0);
+				/* assert the referenced object is locked */
+				Assert(LockHeldByMe(&tag, AccessShareLock, false));
+			}
+			else
+			{
+				Assert(!IsSharedRelation(referenced->objectId));
+
+				/*
+				 * Assert the referenced object is locked if it should be
+				 * visible (see the comment related to LockNotPinnedObject()
+				 * in TypeCreate()).
+				 */
+				Assert(!ObjectByIdExist(referenced) ||
+					   CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -238,6 +270,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -705,7 +738,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index bfcfa643464..ba6aa332187 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index fe0490259e9..c3999bdce87 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new function entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 41ffd494c81..8922b8547e7 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -441,6 +441,7 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 				referenced;
 	List	   *relids = NIL;
 	int			i;
+	bool		locked = false;
 
 	rel = table_open(PublicationRelRelationId, RowExclusiveLock);
 
@@ -503,10 +504,13 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+
+	LockNotPinnedObject(RelationRelationId, relid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -520,6 +524,11 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	while ((i = bms_next_member(attnums, i)) >= 0)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, i);
+		if (!locked)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked = true;
+		}
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -717,10 +726,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 8df73e7ab71..e1538c21468 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index b36f81afb9d..77ff5f06030 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,37 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement() here to ensure the new type entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+
+		/*
+		 * No need to call LockRelationOid() (through LockNotPinnedObject())
+		 * on relationOid as relationOid is set to an InvalidOid or to a new
+		 * Oid not added to pg_class yet (In heap_create_with_catalog(),
+		 * AddNewRelationType() is called before AddNewRelationTuple()).
+		 */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +543,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 874a8fc89ad..b8fb22af6ae 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -383,6 +383,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		LockNotPinnedObject(RelationRelationId, relOid);
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 78c1d4e1b84..e068b127c28 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -499,7 +499,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -803,6 +806,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index 58ed9d216cc..eb9b86d5633 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 99193f5c886..c1a7ecbfab8 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1274,6 +1274,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1282,6 +1283,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1383,6 +1386,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r1);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1391,6 +1396,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+
+				LockNotPinnedObject(RelationRelationId, r2);
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index edc2c988e29..14dab63ef0d 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index ba540e3de5b..01813ac71d5 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -2035,6 +2035,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -2043,6 +2044,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -3079,6 +3081,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3369,6 +3372,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3525,6 +3529,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index c14e038d54f..d6cced22e7a 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index b9fd7683abb..e2155511478 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1461,6 +1461,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1474,6 +1475,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1990,21 +1992,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 5b1753d4681..f601d590d8f 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4488,8 +4488,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			LockNotPinnedObject(RelationRelationId, parentOid);
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			LockNotPinnedObject(RelationRelationId, partitionIdx->rd_index->indrelid);
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index 2c325badf94..72b347e9802 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -299,12 +299,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -726,18 +728,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -746,6 +751,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1487,6 +1493,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement() here to ensure the new operator entry is
+		 * visible when LockNotPinnedObject() will check its existence before
+		 * recording the dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1497,6 +1510,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1505,6 +1519,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1538,6 +1553,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1621,6 +1637,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1629,6 +1646,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 673648f1fc6..59a4715fffe 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 83056960fe4..cf5e1947929 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, table_id);
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 5036ac03639..f4a7e46b714 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index b13ee2b745d..31dba914b87 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1691,6 +1691,8 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(tablerel));
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index a817821bf6d..5b7950d5823 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -88,6 +88,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	bool		build_mcv;
 	bool		build_expressions;
 	bool		requested_type = false;
+	bool		locked_object = false;
 	int			i;
 	ListCell   *cell;
 	ListCell   *cell2;
@@ -536,6 +537,12 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+
+		if (!locked_object)
+		{
+			LockNotPinnedObject(RelationRelationId, relid);
+			locked_object = true;
+		}
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +560,8 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+
+		LockNotPinnedObject(RelationRelationId, relid);
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +582,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 18f64db6e39..77b4d99f711 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3527,6 +3527,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, parentOid);
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7434,7 +7435,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10491,11 +10494,16 @@ addFkConstraint(addFkConstraintSides fkside,
 
 		Assert(fkside != addFkBothSides);
 		if (fkside == addFkReferencedSide)
+		{
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
+		}
 		else
 		{
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -13969,7 +13977,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -15547,6 +15557,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -15566,6 +15577,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -17288,6 +17300,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -18060,14 +18073,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
-								relOid,
-								NamespaceRelationId,
-								oldNspOid,
-								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
+									relOid,
+									NamespaceRelationId,
+									oldNspOid,
+									newNspOid) != 1)
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	else
 		UnlockTuple(classRel, &classTup->t_self, InplaceUpdateTupleLock);
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 7a5ffe32f60..3c1863c0e5b 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1020,8 +1020,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1029,6 +1027,13 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement() here to ensure the new trigger entry is
+	 * visible when LockNotPinnedObject() will check its existence before
+	 * recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1047,6 +1052,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1060,6 +1066,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1072,6 +1079,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+
+		LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1079,6 +1088,8 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+
+			LockNotPinnedObject(RelationRelationId, constrrelid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1093,6 +1104,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1102,8 +1114,11 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+
+			LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1112,12 +1127,19 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	if (columns != NULL)
 	{
 		int			i;
+		bool		locked_object = false;
 
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+
+			if (!locked_object)
+			{
+				LockNotPinnedObject(RelationRelationId, RelationGetRelid(rel));
+				locked_object = true;
+			}
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1257,9 +1279,12 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+
+		LockNotPinnedObject(RelationRelationId, childTableId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index ab16d42ad56..e36c3da1023 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,48 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsstart - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsstart - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prstoken - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prstoken - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsend - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsend - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prsheadline - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prsheadline - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_parser_prslextype - 1] =
 				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			procoid = DatumGetObjectId(values[Anum_pg_ts_parser_prslextype - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +495,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -723,6 +748,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +759,23 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmplinit - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmplinit - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
+			Oid			procoid;
+
 			values[Anum_pg_ts_template_tmpllexize - 1] =
 				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			procoid = DatumGetObjectId(values[Anum_pg_ts_template_tmpllexize - 1]);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -998,6 +1032,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1063,6 +1101,7 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = cfgmap->mapseqno;
 			slot[slot_stored_count]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = cfgmap->mapdict;
 
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 			ExecStoreVirtualTuple(slot[slot_stored_count]);
 			slot_stored_count++;
 
@@ -1156,9 +1195,13 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
+	ScanKeyData skey;
+	SysScanDesc scan;
+	HeapTuple	maptup;
 
 	/* Find the configuration */
 	tup = GetTSConfigTuple(stmt->cfgname);
@@ -1168,7 +1211,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1227,28 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+
+	ScanKeyInit(&skey,
+				Anum_pg_ts_config_map_mapcfg,
+				BTEqualStrategyNumber, F_OIDEQ,
+				ObjectIdGetDatum(cfgId));
+
+	scan = systable_beginscan(relMap, TSConfigMapIndexId, true,
+							  NULL, 1, &skey);
+
+	while (HeapTupleIsValid((maptup = systable_getnext(scan))))
+	{
+		Form_pg_ts_config_map cfgmap = (Form_pg_ts_config_map) GETSTRUCT(maptup);
+
+		LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
+	}
+
+	systable_endscan(scan);
+
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1480,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1524,9 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				/* Lock dependent objects */
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 3cb3ca1cca1..e36ea6d97e0 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1820,6 +1820,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1885,6 +1886,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2698,6 +2700,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4263,10 +4304,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4558,6 +4602,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4606,6 +4651,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 8aa90b0d6fb..14a6468efca 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(RelationRelationId, eventrel_oid);
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index c96aa7c49ef..c664ae4977b 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -277,6 +277,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 0ea7ccf5243..73ee2c6a787 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,8 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -172,6 +174,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 630434b73cf..34d5428433b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 00000000000..820680f5e16
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  dependent object does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 143109aa4da..0e80dfecfb3 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -115,3 +115,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 00000000000..5d04dfe9dc6
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 362f38856d2..7c162c0d455 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2862,11 +2862,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 18:27                                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-14 07:54                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-17 16:24                                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-17 17:57                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-19 14:11                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-21 13:22                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-26 10:24                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-01 09:39                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-02 05:56                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-07-10 07:31                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-08-19 15:35                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-10-28 09:30                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-01-02 08:15                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-02-04 13:24                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2025-05-23 04:20                                                                               ` jian he <jian.universality@gmail.com>
  0 siblings, 0 replies; 93+ messages in thread

From: jian he @ 2025-05-23 04:20 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Robert Haas <robertmhaas@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Tue, Feb 4, 2025 at 9:24 PM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
>
> Hi,
>
> On Thu, Jan 02, 2025 at 08:15:13AM +0000, Bertrand Drouvot wrote:
> > rebased (v18 attached).
>
> Thanks to all of you that have discussed this patch during the developer meeting
> at FOSDEM PGDay last week [1]. I'm attaching a new version to address Álvaro's
> concern about calling getObjectDescription() in the new LockNotPinnedObjectById()
> function. This call was being used to provide a "meaningful" error message but
> we agreed to provide the object OID instead (as anyway the object is dropped).
>
> Note that the OIDs are reported as "errdetail" to ensure the isolation tests
> added in this patch remain stable (output does not depend of the actual OIDs
> values).
>
> A quick sum up about this patch:
>
> A. Locking is done exclusively with LockNotPinnedObject(Oid classid, Oid objid)
> so that it's now always clear what object we want to acquire a lock for. It means
> that we are not manipulating directly an object address or a list of objects
> address as it was the case when the locking was done "directly" within the
> dependency code.
>
> B. A special case is done for objects that belong to the RelationRelationId class.
> For those, we should be in one of the two following cases that would already
> prevent the relation to be dropped:
>
>  B1. The relation is already locked (could be an existing relation or a relation
>  that we are creating).
>
>  B2. The relation is protected indirectly (i.e an index protected by a lock on
>  its table, a table protected by a lock on a function that depends the table...)
>
> To avoid any risks for the RelationRelationId class case, we acquire a lock if
> there is none. That may add unnecessary lock for B2. but that seems worth it.
>
> That's a lot of mechanical changes so that's easy to miss one or to do it
> wrong but:
>
> 1. I did my best to avoid that
> 2. assertions are added in recordMultipleDependencies() to "ensure" the object
> is locked
> 3. even if one case is missing (that is not catched by the assertions because
> the dependency is not covered in the tests, not sure that exists though), then it
> just means that we could be in the current state (orphaned dependency), not worst
> than that
>
> During the meeting a question has been raised regarding the number of locks
> increase. This has already been discussed in [2] and I think that the outcome
> is that the default max_locks_per_transaction value (64) is probably still
> enough in real life (and even if it is not then it can be increased to satisfy
> the requirements).
>
> [1]: https://2025.fosdempgday.org/devmeeting
> [2]: https://www.postgresql.org/message-id/CA%2BTgmoaFPUubBBk52Qp2wkoL7JX7OjhewiK%2B7LSot7%3DrecbzzQ%40ma...
>

hi.
I plan to play around with v19.
but i can not build based on it.

related error message:

running bootstrap script ... ok
performing post-bootstrap initialization ... TRAP: failed
Assert("LockHeldByMe(&tag, AccessShareLock, false)"), File:
"../../Desktop/pg_src/src1/postgres/src/backend/catalog/pg_depend.c",
Line: 116, PID: 1118343
/home/jian/postgres/regression1/bin/postgres(ExceptionalCondition+0xf3)[0xe66090]
/home/jian/postgres/regression1/bin/postgres(recordMultipleDependencies+0x17f)[0x6ae34d]
/home/jian/postgres/regression1/bin/postgres(record_object_address_dependencies+0x4e)[0x66b333]
/home/jian/postgres/regression1/bin/postgres(ProcedureCreate+0x2443)[0x6b9ad7]
/home/jian/postgres/regression1/bin/postgres(CreateFunction+0xf91)[0x73a7ef]
/home/jian/postgres/regression1/bin/postgres[0xbcba68]
/home/jian/postgres/regression1/bin/postgres(standard_ProcessUtility+0x170c)[0xbc9fb7]
/home/jian/postgres/regression1/bin/postgres(ProcessUtility+0x184)[0xbc889b]
/home/jian/postgres/regression1/bin/postgres[0xbc6821]
/home/jian/postgres/regression1/bin/postgres[0xbc6bbd]
/home/jian/postgres/regression1/bin/postgres(PortalRun+0x3f4)[0xbc5bda]
/home/jian/postgres/regression1/bin/postgres[0xbbae37]
/home/jian/postgres/regression1/bin/postgres(PostgresMain+0x1110)[0xbc2feb]
/home/jian/postgres/regression1/bin/postgres(PostgresMain+0x0)[0xbc1edb]
/home/jian/postgres/regression1/bin/postgres(main+0x4cf)[0x8e98b1]
/lib/x86_64-linux-gnu/libc.so.6(+0x29d90)[0x71d95a829d90]
/lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0x80)[0x71d95a829e40]
/home/jian/postgres/regression1/bin/postgres(_start+0x25)[0x4af1c5]
Aborted (core dumped)
child process exited with exit code 134





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-23 04:19                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-23 18:10                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-06 05:56                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-06 20:00                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-07 08:41                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-06-13 14:49                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-06-13 16:52                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-06-17 10:50                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2024-06-17 10:50 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jun 13, 2024 at 04:52:09PM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Thu, Jun 13, 2024 at 10:49:34AM -0400, Robert Haas wrote:
> > On Fri, Jun 7, 2024 at 4:41 AM Bertrand Drouvot
> > <bertranddrouvot.pg@gmail.com> wrote:
> > > Do you still find the code hard to maintain with v9?
> > 
> > I don't think it substantially changes my concerns as compared with
> > the earlier version.
> 
> Thanks for the feedback, I'll give it more thoughts.

Please find attached v10 that puts the object locking outside of the dependency
code.

It's done that way except for:

recordDependencyOnExpr() 
recordDependencyOnSingleRelExpr()
makeConfigurationDependencies()

The reason is that I think that it would need part of the logic that his inside
the above functions to be duplicated and I'm not sure that's worth it.

For example, we would probably need to:

- make additional calls to find_expr_references_walker() 
- make additional scan on the config map

It's also not done outside of recordDependencyOnCurrentExtension() as:

1. I think it is clear enough that way (as it is clear that the lock is taken on
a ExtensionRelationId object class).
2. why to include "commands/extension.h" in more places (locking would
depend of "creating_extension" and "CurrentExtensionObject"), while 1.?

Remarks:

1. depLockAndCheckObject() and friends in v9 have been renamed to
LockNotPinnedObject() and friends (as the vast majority of their calls are now
done outside of the dependency code).

2. regarding the concern around RelationRelationId (discussed in [1]), v10 adds
a comment "XXX Do we need a lock for RelationRelationId?" at the places we
may want to lock this object class. I did not think about it yet (but will do),
I only added this comment at multiple places.

I think that v10 is easier to follow (as compare to v9) as we can easily see for
which object class we'll put a lock on.

Thoughts?

[1]: https://www.postgresql.org/message-id/Zmv3TPfJAyQXhIdu%40ip-10-97-1-34.eu-west-3.compute.internal

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v10-0001-Avoid-orphaned-objects-dependencies.patch (93.6K, ../../ZnAVEBhlGvpDDVOD@ip-10-97-1-34.eu-west-3.compute.internal/2-v10-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From dc75e3255803617d21c55d77dc218904bd729d81 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v10] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place before the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/aclchk.c                  |   1 +
 src/backend/catalog/dependency.c              | 109 ++++++++++++++-
 src/backend/catalog/heap.c                    |   8 ++
 src/backend/catalog/index.c                   |  16 +++
 src/backend/catalog/objectaddress.c           |  57 ++++++++
 src/backend/catalog/pg_aggregate.c            |   9 ++
 src/backend/catalog/pg_attrdef.c              |   1 +
 src/backend/catalog/pg_cast.c                 |   5 +
 src/backend/catalog/pg_collation.c            |   1 +
 src/backend/catalog/pg_constraint.c           |  11 ++
 src/backend/catalog/pg_conversion.c           |   2 +
 src/backend/catalog/pg_depend.c               |  27 +++-
 src/backend/catalog/pg_operator.c             |  19 +++
 src/backend/catalog/pg_proc.c                 |  17 ++-
 src/backend/catalog/pg_publication.c          |   5 +
 src/backend/catalog/pg_range.c                |   6 +
 src/backend/catalog/pg_type.c                 |  33 +++++
 src/backend/catalog/toasting.c                |   1 +
 src/backend/commands/alter.c                  |   4 +
 src/backend/commands/amcmds.c                 |   1 +
 src/backend/commands/cluster.c                |   5 +
 src/backend/commands/event_trigger.c          |   1 +
 src/backend/commands/extension.c              |   5 +
 src/backend/commands/foreigncmds.c            |   7 +
 src/backend/commands/functioncmds.c           |   6 +
 src/backend/commands/indexcmds.c              |   2 +
 src/backend/commands/opclasscmds.c            |  18 +++
 src/backend/commands/operatorcmds.c           |  30 ++++
 src/backend/commands/policy.c                 |   2 +
 src/backend/commands/proclang.c               |   3 +
 src/backend/commands/sequence.c               |   1 +
 src/backend/commands/statscmds.c              |   3 +
 src/backend/commands/tablecmds.c              |  32 +++--
 src/backend/commands/trigger.c                |  18 ++-
 src/backend/commands/tsearchcmds.c            |  81 +++++++----
 src/backend/commands/typecmds.c               |  84 ++++++++++++
 src/backend/rewrite/rewriteDefine.c           |   1 +
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   7 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 43 files changed, 813 insertions(+), 47 deletions(-)
  31.4% src/backend/catalog/
  36.4% src/backend/commands/
  18.5% src/test/isolation/expected/
  11.5% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 143876b77f..5a614f25ff 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -1413,6 +1413,7 @@ SetDefaultACL(InternalDefaultACL *iacls)
 				referenced.objectId = iacls->nspid;
 				referenced.objectSubId = 0;
 
+				LockNotPinnedObject(NamespaceRelationId, iacls->nspid);
 				recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 			}
 		}
diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 0489cbabcb..abf8b92a6d 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1519,6 +1519,84 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+LockNotPinnedObjectById(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	if (isObjectPinned(object))
+		return;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object))
+	{
+		if (object_description)
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("%s does not exist", object_description)));
+		else
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("a dependent object does not exist")));
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
+void
+LockNotPinnedObjectsById(const ObjectAddress *object, int nobject)
+{
+	int			i;
+
+	if (nobject < 0)
+		return;
+
+	for (i = 0; i < nobject; i++, object++)
+		LockNotPinnedObjectById(object);
+
+	return;
+}
+
+
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ */
+void
+LockNotPinnedObject(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObjectById(&object);
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
@@ -1564,13 +1642,8 @@ recordDependencyOnExpr(const ObjectAddress *depender,
 	/* Scan the expression tree for referenceable objects */
 	find_expr_references_walker(expr, &context);
 
-	/* Remove any duplicates */
-	eliminate_duplicate_dependencies(context.addrs);
-
-	/* And record 'em */
-	recordMultipleDependencies(depender,
-							   context.addrs->refs, context.addrs->numrefs,
-							   behavior);
+	/* Record all of them (this includes duplicate elimination) */
+	lock_record_object_address_dependencies(depender, context.addrs, behavior);
 
 	free_object_addresses(context.addrs);
 }
@@ -1654,14 +1727,19 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 
 		/* Record the self-dependencies with the appropriate direction */
 		if (!reverse_self)
+		{
+			LockNotPinnedObjectsById(self_addrs->refs, self_addrs->numrefs);
 			recordMultipleDependencies(depender,
 									   self_addrs->refs, self_addrs->numrefs,
 									   self_behavior);
+		}
 		else
 		{
 			/* Can't use recordMultipleDependencies, so do it the hard way */
 			int			selfref;
 
+			LockNotPinnedObjectById(depender);
+
 			for (selfref = 0; selfref < self_addrs->numrefs; selfref++)
 			{
 				ObjectAddress *thisobj = self_addrs->refs + selfref;
@@ -1674,6 +1752,7 @@ recordDependencyOnSingleRelExpr(const ObjectAddress *depender,
 	}
 
 	/* Record the external dependencies */
+	LockNotPinnedObjectsById(context.addrs->refs, context.addrs->numrefs);
 	recordMultipleDependencies(depender,
 							   context.addrs->refs, context.addrs->numrefs,
 							   behavior);
@@ -2734,6 +2813,22 @@ stack_address_present_add_flags(const ObjectAddress *object,
 	return result;
 }
 
+/*
+ * Record multiple dependencies from an ObjectAddresses array and lock the
+ * referenced objects, after first removing any duplicates.
+ */
+void
+lock_record_object_address_dependencies(const ObjectAddress *depender,
+										ObjectAddresses *referenced,
+										DependencyType behavior)
+{
+	eliminate_duplicate_dependencies(referenced);
+	LockNotPinnedObjectsById(referenced->refs, referenced->numrefs);
+	recordMultipleDependencies(depender,
+							   referenced->refs, referenced->numrefs,
+							   behavior);
+}
+
 /*
  * Record multiple dependencies from an ObjectAddresses array, after first
  * removing any duplicates.
diff --git a/src/backend/catalog/heap.c b/src/backend/catalog/heap.c
index a122bbffce..72443710d3 100644
--- a/src/backend/catalog/heap.c
+++ b/src/backend/catalog/heap.c
@@ -843,6 +843,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		ObjectAddressSubSet(myself, RelationRelationId, new_rel_oid, i + 1);
 		ObjectAddressSet(referenced, TypeRelationId,
 						 tupdesc->attrs[i].atttypid);
+		LockNotPinnedObject(TypeRelationId, tupdesc->attrs[i].atttypid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 		/* The default collation is pinned, so don't bother recording it */
@@ -851,6 +852,7 @@ AddNewAttributeTuples(Oid new_rel_oid,
 		{
 			ObjectAddressSet(referenced, CollationRelationId,
 							 tupdesc->attrs[i].attcollation);
+			LockNotPinnedObject(CollationRelationId, tupdesc->attrs[i].attcollation);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1451,11 +1453,13 @@ heap_create_with_catalog(const char *relname,
 
 		ObjectAddressSet(referenced, NamespaceRelationId, relnamespace);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(NamespaceRelationId, relnamespace);
 
 		if (reloftypeid)
 		{
 			ObjectAddressSet(referenced, TypeRelationId, reloftypeid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TypeRelationId, reloftypeid);
 		}
 
 		/*
@@ -1469,6 +1473,7 @@ heap_create_with_catalog(const char *relname,
 		{
 			ObjectAddressSet(referenced, AccessMethodRelationId, accessmtd);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(AccessMethodRelationId, accessmtd);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -3383,6 +3388,7 @@ StorePartitionKey(Relation rel,
 	{
 		ObjectAddressSet(referenced, OperatorClassRelationId, partopclass[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorClassRelationId, partopclass[i]);
 
 		/* The default collation is pinned, so don't bother recording it */
 		if (OidIsValid(partcollation[i]) &&
@@ -3390,6 +3396,7 @@ StorePartitionKey(Relation rel,
 		{
 			ObjectAddressSet(referenced, CollationRelationId, partcollation[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(CollationRelationId, partcollation[i]);
 		}
 	}
 
@@ -3409,6 +3416,7 @@ StorePartitionKey(Relation rel,
 
 		ObjectAddressSubSet(referenced, RelationRelationId,
 							RelationGetRelid(rel), partattrs[i]);
+		/* Do we need a lock on RelationRelationId? */
 		recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/catalog/index.c b/src/backend/catalog/index.c
index 55fdde4b24..b89c217a09 100644
--- a/src/backend/catalog/index.c
+++ b/src/backend/catalog/index.c
@@ -1127,6 +1127,7 @@ index_create(Relation heapRelation,
 										heapRelationId,
 										indexInfo->ii_IndexAttrNumbers[i]);
 					add_exact_object_address(&referenced, addrs);
+					/* XXX Do we need a lock for RelationRelationId? */
 					have_simple_col = true;
 				}
 			}
@@ -1141,6 +1142,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, RelationRelationId,
 								 heapRelationId);
+				/* XXX Do we need a lock for RelationRelationId? */
 				add_exact_object_address(&referenced, addrs);
 			}
 
@@ -1157,9 +1159,11 @@ index_create(Relation heapRelation,
 		if (OidIsValid(parentIndexRelid))
 		{
 			ObjectAddressSet(referenced, RelationRelationId, parentIndexRelid);
+			/* XXX Do we need a lock for RelationRelationId? */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 
 			ObjectAddressSet(referenced, RelationRelationId, heapRelationId);
+			/* XXX Do we need a lock for RelationRelationId? */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 
@@ -1175,6 +1179,7 @@ index_create(Relation heapRelation,
 			{
 				ObjectAddressSet(referenced, CollationRelationId, collationIds[i]);
 				add_exact_object_address(&referenced, addrs);
+				LockNotPinnedObject(CollationRelationId, collationIds[i]);
 			}
 		}
 
@@ -1183,6 +1188,7 @@ index_create(Relation heapRelation,
 		{
 			ObjectAddressSet(referenced, OperatorClassRelationId, opclassIds[i]);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(OperatorClassRelationId, opclassIds[i]);
 		}
 
 		record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -1987,6 +1993,14 @@ index_constraint_create(Relation heapRelation,
 	 */
 	ObjectAddressSet(myself, ConstraintRelationId, conOid);
 	ObjectAddressSet(idxaddr, RelationRelationId, indexRelationId);
+
+	/*
+	 * CommandCounterIncrement here to ensure the new constraint entry is
+	 * visible when we'll check of object existence when recording the
+	 * dependencies.
+	 */
+	CommandCounterIncrement();
+	LockNotPinnedObject(ConstraintRelationId, conOid);
 	recordDependencyOn(&idxaddr, &myself, DEPENDENCY_INTERNAL);
 
 	/*
@@ -1998,9 +2012,11 @@ index_constraint_create(Relation heapRelation,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstraintId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstraintId);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(heapRelation));
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..6d7abd3738 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,63 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address)
+{
+	HeapTuple	tuple;
+	int			cache;
+	const ObjectPropertyType *property;
+
+	property = get_object_property_data(address->classId);
+
+	cache = property->oid_catcache_id;
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  NULL, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 90fc7db949..a47e3c5507 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -748,12 +748,14 @@ AggregateCreate(const char *aggName,
 	/* Depends on transition function */
 	ObjectAddressSet(referenced, ProcedureRelationId, transfn);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, transfn);
 
 	/* Depends on final function, if any */
 	if (OidIsValid(finalfn))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, finalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, finalfn);
 	}
 
 	/* Depends on combine function, if any */
@@ -761,6 +763,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, combinefn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, combinefn);
 	}
 
 	/* Depends on serialization function, if any */
@@ -768,6 +771,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, serialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, serialfn);
 	}
 
 	/* Depends on deserialization function, if any */
@@ -775,6 +779,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, deserialfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, deserialfn);
 	}
 
 	/* Depends on forward transition function, if any */
@@ -782,6 +787,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mtransfn);
 	}
 
 	/* Depends on inverse transition function, if any */
@@ -789,6 +795,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, minvtransfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, minvtransfn);
 	}
 
 	/* Depends on final function, if any */
@@ -796,6 +803,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, mfinalfn);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, mfinalfn);
 	}
 
 	/* Depends on sort operator, if any */
@@ -803,6 +811,7 @@ AggregateCreate(const char *aggName,
 	{
 		ObjectAddressSet(referenced, OperatorRelationId, sortop);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(OperatorRelationId, sortop);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/catalog/pg_attrdef.c b/src/backend/catalog/pg_attrdef.c
index 003ae70b4d..80db2c0c20 100644
--- a/src/backend/catalog/pg_attrdef.c
+++ b/src/backend/catalog/pg_attrdef.c
@@ -178,6 +178,7 @@ StoreAttrDefault(Relation rel, AttrNumber attnum,
 	colobject.objectId = RelationGetRelid(rel);
 	colobject.objectSubId = attnum;
 
+	/* XXX Do we need a lock for RelationRelationId? */
 	recordDependencyOn(&defobject, &colobject,
 					   attgenerated ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5a5b855d51..d3707e424c 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -97,16 +97,19 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on source type */
 	ObjectAddressSet(referenced, TypeRelationId, sourcetypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, sourcetypeid);
 
 	/* dependency on target type */
 	ObjectAddressSet(referenced, TypeRelationId, targettypeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, targettypeid);
 
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, funcid);
 	}
 
 	/* dependencies on casts required for function */
@@ -114,11 +117,13 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	{
 		ObjectAddressSet(referenced, CastRelationId, incastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, incastid);
 	}
 	if (OidIsValid(outcastid))
 	{
 		ObjectAddressSet(referenced, CastRelationId, outcastid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CastRelationId, outcastid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, behavior);
diff --git a/src/backend/catalog/pg_collation.c b/src/backend/catalog/pg_collation.c
index 7f2f701229..78498b8c20 100644
--- a/src/backend/catalog/pg_collation.c
+++ b/src/backend/catalog/pg_collation.c
@@ -218,6 +218,7 @@ CollationCreate(const char *collname, Oid collnamespace,
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = collnamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, collnamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_constraint.c b/src/backend/catalog/pg_constraint.c
index 3baf9231ed..4afa9a1d69 100644
--- a/src/backend/catalog/pg_constraint.c
+++ b/src/backend/catalog/pg_constraint.c
@@ -257,12 +257,14 @@ CreateConstraintEntry(const char *constraintName,
 				ObjectAddressSubSet(relobject, RelationRelationId, relId,
 									constraintKey[i]);
 				add_exact_object_address(&relobject, addrs_auto);
+				/* XXX Do we need a lock for RelationRelationId?? */
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, relId);
 			add_exact_object_address(&relobject, addrs_auto);
+			/* XXX Do we need a lock for RelationRelationId?? */
 		}
 	}
 
@@ -275,6 +277,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(domobject, TypeRelationId, domainId);
 		add_exact_object_address(&domobject, addrs_auto);
+		LockNotPinnedObject(TypeRelationId, domainId);
 	}
 
 	record_object_address_dependencies(&conobject, addrs_auto,
@@ -299,12 +302,14 @@ CreateConstraintEntry(const char *constraintName,
 				ObjectAddressSubSet(relobject, RelationRelationId,
 									foreignRelId, foreignKey[i]);
 				add_exact_object_address(&relobject, addrs_normal);
+				/* XXX Do we need a lock for RelationRelationId? */
 			}
 		}
 		else
 		{
 			ObjectAddressSet(relobject, RelationRelationId, foreignRelId);
 			add_exact_object_address(&relobject, addrs_normal);
+			/* XXX Do we need a lock for RelationRelationId? */
 		}
 	}
 
@@ -320,6 +325,7 @@ CreateConstraintEntry(const char *constraintName,
 
 		ObjectAddressSet(relobject, RelationRelationId, indexRelId);
 		add_exact_object_address(&relobject, addrs_normal);
+		/* XXX Do we need a lock for RelationRelationId?? */
 	}
 
 	if (foreignNKeys > 0)
@@ -339,15 +345,18 @@ CreateConstraintEntry(const char *constraintName,
 		{
 			oprobject.objectId = pfEqOp[i];
 			add_exact_object_address(&oprobject, addrs_normal);
+			LockNotPinnedObject(OperatorRelationId, pfEqOp[i]);
 			if (ppEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ppEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ppEqOp[i]);
 			}
 			if (ffEqOp[i] != pfEqOp[i])
 			{
 				oprobject.objectId = ffEqOp[i];
 				add_exact_object_address(&oprobject, addrs_normal);
+				LockNotPinnedObject(OperatorRelationId, ffEqOp[i]);
 			}
 		}
 	}
@@ -858,9 +867,11 @@ ConstraintSetParentConstraint(Oid childConstrId,
 		ObjectAddressSet(depender, ConstraintRelationId, childConstrId);
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrId);
+		LockNotPinnedObject(ConstraintRelationId, parentConstrId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/catalog/pg_conversion.c b/src/backend/catalog/pg_conversion.c
index 0770878eac..25881654d6 100644
--- a/src/backend/catalog/pg_conversion.c
+++ b/src/backend/catalog/pg_conversion.c
@@ -116,12 +116,14 @@ ConversionCreate(const char *conname, Oid connamespace,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = conproc;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, conproc);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = connamespace;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, connamespace);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* create dependency on owner */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index cfd7ef51df..b97aa2ab91 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -20,21 +20,20 @@
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
+#include "catalog/pg_auth_members.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
 #include "catalog/pg_extension.h"
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
 #include "utils/rel.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
-
 /*
  * Record a dependency between 2 objects via their respective objectAddress.
  * The first argument is the dependent object, the second the one it
@@ -100,6 +99,25 @@ recordMultipleDependencies(const ObjectAddress *depender,
 	slot_init_count = 0;
 	for (i = 0; i < nreferenced; i++, referenced++)
 	{
+#ifdef USE_ASSERT_CHECKING
+		LOCKTAG		tag;
+
+		SET_LOCKTAG_OBJECT(tag,
+						   MyDatabaseId,
+						   referenced->classId,
+						   referenced->objectId,
+						   0);
+
+		/*
+		 * Assert the referenced object is locked (see
+		 * LockNotPinnedObjectById()).
+		 */
+		Assert(isObjectPinned(referenced) ||
+			   referenced->classId == RelationRelationId ||
+			   referenced->classId == AuthMemRelationId ||
+			   LockHeldByMe(&tag, AccessShareLock));
+#endif
+
 		/*
 		 * If the referenced object is pinned by the system, there's no real
 		 * need to record dependencies on it.  This saves lots of space in
@@ -239,6 +257,7 @@ recordDependencyOnCurrentExtension(const ObjectAddress *object,
 		extension.objectId = CurrentExtensionObject;
 		extension.objectSubId = 0;
 
+		LockNotPinnedObject(ExtensionRelationId, CurrentExtensionObject);
 		recordDependencyOn(object, &extension, DEPENDENCY_EXTENSION);
 	}
 }
@@ -706,7 +725,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 65b45a424a..e8374eec88 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -251,6 +251,16 @@ OperatorShellMake(const char *operatorName,
 	values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(InvalidOid);
 	values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(InvalidOid);
 
+	/* Lock dependent objects */
+	if (OidIsValid(operatorNamespace))
+		LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+
+	if (OidIsValid(leftTypeId))
+		LockNotPinnedObject(TypeRelationId, leftTypeId);
+
+	if (OidIsValid(rightTypeId))
+		LockNotPinnedObject(TypeRelationId, rightTypeId);
+
 	/*
 	 * create a new operator tuple
 	 */
@@ -513,6 +523,15 @@ OperatorCreate(const char *operatorName,
 		CatalogTupleInsert(pg_operator_desc, tup);
 	}
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, operatorNamespace);
+	LockNotPinnedObject(TypeRelationId, leftTypeId);
+	LockNotPinnedObject(TypeRelationId, rightTypeId);
+	LockNotPinnedObject(TypeRelationId, operResultType);
+	LockNotPinnedObject(ProcedureRelationId, procedureId);
+	LockNotPinnedObject(ProcedureRelationId, restrictionId);
+	LockNotPinnedObject(ProcedureRelationId, joinId);
+
 	/* Add dependencies for the entry */
 	address = makeOperatorDependencies(tup, true, isUpdate);
 
diff --git a/src/backend/catalog/pg_proc.c b/src/backend/catalog/pg_proc.c
index 528c17cd7f..9cceb6413b 100644
--- a/src/backend/catalog/pg_proc.c
+++ b/src/backend/catalog/pg_proc.c
@@ -593,6 +593,13 @@ ProcedureCreate(const char *procedureName,
 	if (is_update)
 		deleteDependencyRecordsFor(ProcedureRelationId, retval, true);
 
+	/*
+	 * CommandCounterIncrement here to ensure the new function entry is
+	 * visible when we'll check of object existence when recording the
+	 * dependencies.
+	 */
+	CommandCounterIncrement();
+
 	addrs = new_object_addresses();
 
 	ObjectAddressSet(myself, ProcedureRelationId, retval);
@@ -600,20 +607,24 @@ ProcedureCreate(const char *procedureName,
 	/* dependency on namespace */
 	ObjectAddressSet(referenced, NamespaceRelationId, procNamespace);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(NamespaceRelationId, procNamespace);
 
 	/* dependency on implementation language */
 	ObjectAddressSet(referenced, LanguageRelationId, languageObjectId);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, languageObjectId);
 
 	/* dependency on return type */
 	ObjectAddressSet(referenced, TypeRelationId, returnType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, returnType);
 
 	/* dependency on transform used by return type, if any */
 	if ((trfid = get_transform_oid(returnType, languageObjectId, true)))
 	{
 		ObjectAddressSet(referenced, TransformRelationId, trfid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TransformRelationId, trfid);
 	}
 
 	/* dependency on parameter types */
@@ -621,12 +632,14 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, TypeRelationId, allParams[i]);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(TypeRelationId, allParams[i]);
 
 		/* dependency on transform used by parameter type, if any */
 		if ((trfid = get_transform_oid(allParams[i], languageObjectId, true)))
 		{
 			ObjectAddressSet(referenced, TransformRelationId, trfid);
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TransformRelationId, trfid);
 		}
 	}
 
@@ -635,6 +648,7 @@ ProcedureCreate(const char *procedureName,
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, prosupport);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, prosupport);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -674,9 +688,6 @@ ProcedureCreate(const char *procedureName,
 		ArrayType  *set_items = NULL;
 		int			save_nestlevel = 0;
 
-		/* Advance command counter so new tuple can be seen by validator */
-		CommandCounterIncrement();
-
 		/*
 		 * Set per-function configuration parameters so that the validation is
 		 * done with the environment the function expects.  However, if
diff --git a/src/backend/catalog/pg_publication.c b/src/backend/catalog/pg_publication.c
index 0602398a54..5e16c0fcef 100644
--- a/src/backend/catalog/pg_publication.c
+++ b/src/backend/catalog/pg_publication.c
@@ -438,10 +438,12 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the relation */
 	ObjectAddressSet(referenced, RelationRelationId, relid);
+	/* XXX Do we need a lock for RelationRelationId? */
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the objects mentioned in the qualifications */
@@ -454,6 +456,7 @@ publication_add_relation(Oid pubid, PublicationRelInfo *pri,
 	for (int i = 0; i < natts; i++)
 	{
 		ObjectAddressSubSet(referenced, RelationRelationId, relid, attarray[i]);
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -661,10 +664,12 @@ publication_add_schema(Oid pubid, Oid schemaid, bool if_not_exists)
 
 	/* Add dependency on the publication */
 	ObjectAddressSet(referenced, PublicationRelationId, pubid);
+	LockNotPinnedObject(PublicationRelationId, pubid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Add dependency on the schema */
 	ObjectAddressSet(referenced, NamespaceRelationId, schemaid);
+	LockNotPinnedObject(NamespaceRelationId, schemaid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* Close the table */
diff --git a/src/backend/catalog/pg_range.c b/src/backend/catalog/pg_range.c
index 501a6ba410..e5b5a0b6f8 100644
--- a/src/backend/catalog/pg_range.c
+++ b/src/backend/catalog/pg_range.c
@@ -70,26 +70,31 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 
 	ObjectAddressSet(referenced, TypeRelationId, rangeSubType);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, rangeSubType);
 
 	ObjectAddressSet(referenced, OperatorClassRelationId, rangeSubOpclass);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(OperatorClassRelationId, rangeSubOpclass);
 
 	if (OidIsValid(rangeCollation))
 	{
 		ObjectAddressSet(referenced, CollationRelationId, rangeCollation);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(CollationRelationId, rangeCollation);
 	}
 
 	if (OidIsValid(rangeCanonical))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeCanonical);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeCanonical);
 	}
 
 	if (OidIsValid(rangeSubDiff))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, rangeSubDiff);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, rangeSubDiff);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
@@ -99,6 +104,7 @@ RangeCreate(Oid rangeTypeOid, Oid rangeSubType, Oid rangeCollation,
 	referencing.classId = TypeRelationId;
 	referencing.objectId = multirangeTypeOid;
 	referencing.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, rangeTypeOid);
 	recordDependencyOn(&referencing, &myself, DEPENDENCY_INTERNAL);
 
 	table_close(pg_range, RowExclusiveLock);
diff --git a/src/backend/catalog/pg_type.c b/src/backend/catalog/pg_type.c
index 395dec8ed8..92614cdaaa 100644
--- a/src/backend/catalog/pg_type.c
+++ b/src/backend/catalog/pg_type.c
@@ -157,6 +157,12 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_IN);
+		LockNotPinnedObject(ProcedureRelationId, F_SHELL_OUT);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 NULL,
@@ -166,6 +172,7 @@ TypeShellMake(const char *typeName, Oid typeNamespace, Oid ownerId)
 								 false,
 								 true,	/* make extension dependency */
 								 false);
+	}
 
 	/* Post creation hook for new shell type */
 	InvokeObjectPostCreateHook(TypeRelationId, typoid, 0);
@@ -494,6 +501,31 @@ TypeCreate(Oid newTypeOid,
 	 * Create dependencies.  We can/must skip this in bootstrap mode.
 	 */
 	if (!IsBootstrapProcessingMode())
+	{
+		/*
+		 * CommandCounterIncrement here to ensure the new type  entry is
+		 * visible when we'll check of object existence when recording the
+		 * dependencies.
+		 */
+		CommandCounterIncrement();
+
+		/* Lock dependent objects */
+		LockNotPinnedObject(NamespaceRelationId, typeNamespace);
+		LockNotPinnedObject(ProcedureRelationId, inputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, outputProcedure);
+		LockNotPinnedObject(ProcedureRelationId, receiveProcedure);
+		LockNotPinnedObject(ProcedureRelationId, sendProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodinProcedure);
+		LockNotPinnedObject(ProcedureRelationId, typmodoutProcedure);
+		LockNotPinnedObject(ProcedureRelationId, analyzeProcedure);
+		LockNotPinnedObject(ProcedureRelationId, subscriptProcedure);
+		LockNotPinnedObject(TypeRelationId, baseType);
+		LockNotPinnedObject(CollationRelationId, typeCollation);
+		LockNotPinnedObject(TypeRelationId, elementType);
+		/* XXX Do we need a lock for RelationRelationId? */
+		if (relationKind == RELKIND_COMPOSITE_TYPE)
+			LockNotPinnedObject(TypeRelationId, typeObjectId);
+
 		GenerateTypeDependencies(tup,
 								 pg_type_desc,
 								 (defaultTypeBin ?
@@ -505,6 +537,7 @@ TypeCreate(Oid newTypeOid,
 								 isDependentType,
 								 true,	/* make extension dependency */
 								 rebuildDeps);
+	}
 
 	/* Post creation hook for new type */
 	InvokeObjectPostCreateHook(TypeRelationId, typeObjectId, 0);
diff --git a/src/backend/catalog/toasting.c b/src/backend/catalog/toasting.c
index 738bc46ae8..4a708030ac 100644
--- a/src/backend/catalog/toasting.c
+++ b/src/backend/catalog/toasting.c
@@ -367,6 +367,7 @@ create_toast_table(Relation rel, Oid toastOid, Oid toastIndexOid,
 		toastobject.objectId = toast_relid;
 		toastobject.objectSubId = 0;
 
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&toastobject, &baseobject, DEPENDENCY_INTERNAL);
 	}
 
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 4f99ebb447..57e86f576a 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -501,7 +501,10 @@ ExecAlterObjectDependsStmt(AlterObjectDependsStmt *stmt, ObjectAddress *refAddre
 		currexts = getAutoExtensionsOfObject(address.classId,
 											 address.objectId);
 		if (!list_member_oid(currexts, refAddr.objectId))
+		{
+			LockNotPinnedObject(refAddr.classId, refAddr.objectId);
 			recordDependencyOn(&address, &refAddr, DEPENDENCY_AUTO_EXTENSION);
+		}
 	}
 
 	return address;
@@ -807,6 +810,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 	pfree(replaces);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(classId, objid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for object %u",
diff --git a/src/backend/commands/amcmds.c b/src/backend/commands/amcmds.c
index aaa0f9a1dc..8616a7c9fa 100644
--- a/src/backend/commands/amcmds.c
+++ b/src/backend/commands/amcmds.c
@@ -104,6 +104,7 @@ CreateAccessMethod(CreateAmStmt *stmt)
 	referenced.objectId = amhandler;
 	referenced.objectSubId = 0;
 
+	LockNotPinnedObject(ProcedureRelationId, amhandler);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnCurrentExtension(&myself, false);
diff --git a/src/backend/commands/cluster.c b/src/backend/commands/cluster.c
index 78f96789b0..b54a04f4b0 100644
--- a/src/backend/commands/cluster.c
+++ b/src/backend/commands/cluster.c
@@ -1272,6 +1272,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 	 */
 	if (relam1 != relam2)
 	{
+		LockNotPinnedObject(AccessMethodRelationId, relam2);
 		if (changeDependencyFor(RelationRelationId,
 								r1,
 								AccessMethodRelationId,
@@ -1280,6 +1281,8 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			elog(ERROR, "could not change access method dependency for relation \"%s.%s\"",
 				 get_namespace_name(get_rel_namespace(r1)),
 				 get_rel_name(r1));
+
+		LockNotPinnedObject(AccessMethodRelationId, relam1);
 		if (changeDependencyFor(RelationRelationId,
 								r2,
 								AccessMethodRelationId,
@@ -1381,6 +1384,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r1;
 				toastobject.objectId = relform1->reltoastrelid;
+				/* XXX Do we need a lock for RelationRelationId? */
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
@@ -1389,6 +1393,7 @@ swap_relation_files(Oid r1, Oid r2, bool target_is_pg_class,
 			{
 				baseobject.objectId = r2;
 				toastobject.objectId = relform2->reltoastrelid;
+				/* XXX Do we need a lock for RelationRelationId? */
 				recordDependencyOn(&toastobject, &baseobject,
 								   DEPENDENCY_INTERNAL);
 			}
diff --git a/src/backend/commands/event_trigger.c b/src/backend/commands/event_trigger.c
index 7a5ed6b985..8d0cdec59e 100644
--- a/src/backend/commands/event_trigger.c
+++ b/src/backend/commands/event_trigger.c
@@ -327,6 +327,7 @@ insert_event_trigger_tuple(const char *trigname, const char *eventname, Oid evtO
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* Depend on extension, if any. */
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index 1643c8c69a..669a5d6dd8 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -1924,6 +1924,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 	ObjectAddressSet(nsp, NamespaceRelationId, schemaOid);
 	add_exact_object_address(&nsp, refobjs);
+	LockNotPinnedObject(NamespaceRelationId, schemaOid);
 
 	foreach(lc, requiredExtensions)
 	{
@@ -1932,6 +1933,7 @@ InsertExtensionTuple(const char *extName, Oid extOwner,
 
 		ObjectAddressSet(otherext, ExtensionRelationId, reqext);
 		add_exact_object_address(&otherext, refobjs);
+		LockNotPinnedObject(ExtensionRelationId, reqext);
 	}
 
 	/* Record all of them (this includes duplicate elimination) */
@@ -2968,6 +2970,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 	table_close(extRel, RowExclusiveLock);
 
 	/* update dependency to point to the new schema */
+	LockNotPinnedObject(NamespaceRelationId, nspOid);
 	if (changeDependencyFor(ExtensionRelationId, extensionOid,
 							NamespaceRelationId, oldNspOid, nspOid) != 1)
 		elog(ERROR, "could not change schema dependency for extension %s",
@@ -3258,6 +3261,7 @@ ApplyExtensionUpdates(Oid extensionOid,
 			otherext.objectId = reqext;
 			otherext.objectSubId = 0;
 
+			LockNotPinnedObject(ExtensionRelationId, reqext);
 			recordDependencyOn(&myself, &otherext, DEPENDENCY_NORMAL);
 		}
 
@@ -3414,6 +3418,7 @@ ExecAlterExtensionContentsRecurse(AlterExtensionContentsStmt *stmt,
 		/*
 		 * OK, add the dependency.
 		 */
+		LockNotPinnedObject(extension.classId, extension.objectId);
 		recordDependencyOn(&object, &extension, DEPENDENCY_EXTENSION);
 
 		/*
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index cf61bbac1f..735bca486c 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -642,6 +642,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwhandler;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -650,6 +651,7 @@ CreateForeignDataWrapper(ParseState *pstate, CreateFdwStmt *stmt)
 		referenced.classId = ProcedureRelationId;
 		referenced.objectId = fdwvalidator;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -811,6 +813,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwhandler;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwhandler);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -819,6 +822,7 @@ AlterForeignDataWrapper(ParseState *pstate, AlterFdwStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = fdwvalidator;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, fdwvalidator);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -951,6 +955,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	referenced.classId = ForeignDataWrapperRelationId;
 	referenced.objectId = fdw->fdwid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignDataWrapperRelationId, fdw->fdwid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(ForeignServerRelationId, srvId, ownerId);
@@ -1195,6 +1200,7 @@ CreateUserMapping(CreateUserMappingStmt *stmt)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = srv->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, srv->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (OidIsValid(useId))
@@ -1472,6 +1478,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	referenced.classId = ForeignServerRelationId;
 	referenced.objectId = server->serverid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ForeignServerRelationId, server->serverid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	table_close(ftrel, RowExclusiveLock);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 6593fd7d81..8207ef08b3 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -1446,6 +1446,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 		/* Add or replace dependency on support function */
 		if (OidIsValid(procForm->prosupport))
 		{
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			if (changeDependencyFor(ProcedureRelationId, funcOid,
 									ProcedureRelationId, procForm->prosupport,
 									newsupport) != 1)
@@ -1459,6 +1460,7 @@ AlterFunction(ParseState *pstate, AlterFunctionStmt *stmt)
 			referenced.classId = ProcedureRelationId;
 			referenced.objectId = newsupport;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(ProcedureRelationId, newsupport);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_NORMAL);
 		}
 
@@ -1962,21 +1964,25 @@ CreateTransform(CreateTransformStmt *stmt)
 	/* dependency on language */
 	ObjectAddressSet(referenced, LanguageRelationId, langid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(LanguageRelationId, langid);
 
 	/* dependency on type */
 	ObjectAddressSet(referenced, TypeRelationId, typeid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(TypeRelationId, typeid);
 
 	/* dependencies on functions */
 	if (OidIsValid(fromsqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, fromsqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, fromsqlfuncid);
 	}
 	if (OidIsValid(tosqlfuncid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, tosqlfuncid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, tosqlfuncid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 309389e20d..b14eaad7a3 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -4377,8 +4377,10 @@ IndexSetParentIndex(Relation partitionIdx, Oid parentOid)
 			ObjectAddressSet(parentIdx, RelationRelationId, parentOid);
 			ObjectAddressSet(partitionTbl, RelationRelationId,
 							 partitionIdx->rd_index->indrelid);
+			/* Do we lock for RelationRelationId?? */
 			recordDependencyOn(&partIdx, &parentIdx,
 							   DEPENDENCY_PARTITION_PRI);
+			/* Do we lock for RelationRelationId?? */
 			recordDependencyOn(&partIdx, &partitionTbl,
 							   DEPENDENCY_PARTITION_SEC);
 		}
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index b8b5c147c5..ca15106ca9 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -298,12 +298,14 @@ CreateOpFamily(CreateOpFamilyStmt *stmt, const char *opfname,
 	referenced.classId = AccessMethodRelationId;
 	referenced.objectId = amoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(AccessMethodRelationId, amoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on namespace */
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on owner */
@@ -725,18 +727,21 @@ DefineOpClass(CreateOpClassStmt *stmt)
 	referenced.classId = NamespaceRelationId;
 	referenced.objectId = namespaceoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on opfamily */
 	referenced.classId = OperatorFamilyRelationId;
 	referenced.objectId = opfamilyoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(OperatorFamilyRelationId, opfamilyoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 	/* dependency on indexed datatype */
 	referenced.classId = TypeRelationId;
 	referenced.objectId = typeoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	/* dependency on storage datatype */
@@ -745,6 +750,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 		referenced.classId = TypeRelationId;
 		referenced.objectId = storageoid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(TypeRelationId, storageoid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 	}
 
@@ -1486,6 +1492,13 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 
 		heap_freetuple(tup);
 
+		/*
+		 * CommandCounterIncrement here to ensure the new operator entry is
+		 * visible when we'll check of object existence when recording the
+		 * dependencies.
+		 */
+		CommandCounterIncrement();
+
 		/* Make its dependencies */
 		myself.classId = AccessMethodOperatorRelationId;
 		myself.objectId = entryoid;
@@ -1496,6 +1509,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(OperatorRelationId, op->object);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1504,6 +1518,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = op->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, op->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   op->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
@@ -1514,6 +1529,7 @@ storeOperators(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 			referenced.objectId = op->sortfamily;
 			referenced.objectSubId = 0;
 
+			LockNotPinnedObject(OperatorFamilyRelationId, op->sortfamily);
 			recordDependencyOn(&myself, &referenced,
 							   op->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 		}
@@ -1597,6 +1613,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectSubId = 0;
 
 		/* see comments in amapi.h about dependency strength */
+		LockNotPinnedObject(ProcedureRelationId, proc->object);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_NORMAL : DEPENDENCY_AUTO);
 
@@ -1605,6 +1622,7 @@ storeProcedures(List *opfamilyname, Oid amoid, Oid opfamilyoid,
 		referenced.objectId = proc->refobjid;
 		referenced.objectSubId = 0;
 
+		LockNotPinnedObject(referenced.classId, proc->refobjid);
 		recordDependencyOn(&myself, &referenced,
 						   proc->ref_is_hard ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 5872a3e192..58a69e7cc2 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -656,11 +657,15 @@ AlterOperator(AlterOperatorStmt *stmt)
 	{
 		replaces[Anum_pg_operator_oprrest - 1] = true;
 		values[Anum_pg_operator_oprrest - 1] = ObjectIdGetDatum(restrictionOid);
+		if (OidIsValid(restrictionOid))
+			LockNotPinnedObject(ProcedureRelationId, restrictionOid);
 	}
 	if (updateJoin)
 	{
 		replaces[Anum_pg_operator_oprjoin - 1] = true;
 		values[Anum_pg_operator_oprjoin - 1] = ObjectIdGetDatum(joinOid);
+		if (OidIsValid(joinOid))
+			LockNotPinnedObject(ProcedureRelationId, joinOid);
 	}
 	if (OidIsValid(commutatorOid))
 	{
@@ -688,6 +693,31 @@ AlterOperator(AlterOperatorStmt *stmt)
 
 	CatalogTupleUpdate(catalog, &tup->t_self, tup);
 
+
+	/* Lock dependent objects */
+	oprForm = (Form_pg_operator) GETSTRUCT(tup);
+
+	if (OidIsValid(oprForm->oprnamespace))
+		LockNotPinnedObject(NamespaceRelationId, oprForm->oprnamespace);
+
+	if (OidIsValid(oprForm->oprleft))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprleft);
+
+	if (OidIsValid(oprForm->oprright))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprright);
+
+	if (OidIsValid(oprForm->oprresult))
+		LockNotPinnedObject(TypeRelationId, oprForm->oprresult);
+
+	if (OidIsValid(oprForm->oprcode))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprcode);
+
+	if (OidIsValid(oprForm->oprrest))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprrest);
+
+	if (OidIsValid(oprForm->oprjoin))
+		LockNotPinnedObject(ProcedureRelationId, oprForm->oprjoin);
+
 	address = makeOperatorDependencies(tup, false, true);
 
 	if (OidIsValid(commutatorOid) || OidIsValid(negatorOid))
diff --git a/src/backend/commands/policy.c b/src/backend/commands/policy.c
index 6ff3eba824..31e61e4e67 100644
--- a/src/backend/commands/policy.c
+++ b/src/backend/commands/policy.c
@@ -722,6 +722,7 @@ CreatePolicy(CreatePolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	/* XXX Do we need a lock for RelationRelationId? */
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_pstate->p_rtable,
@@ -1053,6 +1054,7 @@ AlterPolicy(AlterPolicyStmt *stmt)
 	myself.objectId = policy_id;
 	myself.objectSubId = 0;
 
+	/* XXX Do we need a lock for RelationRelationId? */
 	recordDependencyOn(&myself, &target, DEPENDENCY_AUTO);
 
 	recordDependencyOnExpr(&myself, qual, qual_parse_rtable, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/proclang.c b/src/backend/commands/proclang.c
index 881f90017e..fadfd9064f 100644
--- a/src/backend/commands/proclang.c
+++ b/src/backend/commands/proclang.c
@@ -190,12 +190,14 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	/* dependency on the PL handler function */
 	ObjectAddressSet(referenced, ProcedureRelationId, handlerOid);
 	add_exact_object_address(&referenced, addrs);
+	LockNotPinnedObject(ProcedureRelationId, handlerOid);
 
 	/* dependency on the inline handler function, if any */
 	if (OidIsValid(inlineOid))
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, inlineOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, inlineOid);
 	}
 
 	/* dependency on the validator function, if any */
@@ -203,6 +205,7 @@ CreateProceduralLanguage(CreatePLangStmt *stmt)
 	{
 		ObjectAddressSet(referenced, ProcedureRelationId, valOid);
 		add_exact_object_address(&referenced, addrs);
+		LockNotPinnedObject(ProcedureRelationId, valOid);
 	}
 
 	record_object_address_dependencies(&myself, addrs, DEPENDENCY_NORMAL);
diff --git a/src/backend/commands/sequence.c b/src/backend/commands/sequence.c
index 28f8522264..b1db4e8933 100644
--- a/src/backend/commands/sequence.c
+++ b/src/backend/commands/sequence.c
@@ -1681,6 +1681,7 @@ process_owned_by(Relation seqrel, List *owned_by, bool for_identity)
 		depobject.classId = RelationRelationId;
 		depobject.objectId = RelationGetRelid(seqrel);
 		depobject.objectSubId = 0;
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&depobject, &refobject, deptype);
 	}
 
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index 1db3ef69d2..372ae02650 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -536,6 +536,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	for (i = 0; i < nattnums; i++)
 	{
 		ObjectAddressSubSet(parentobject, RelationRelationId, relid, attnums[i]);
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -553,6 +554,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	if (!nattnums)
 	{
 		ObjectAddressSet(parentobject, RelationRelationId, relid);
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&myself, &parentobject, DEPENDENCY_AUTO);
 	}
 
@@ -573,6 +575,7 @@ CreateStatistics(CreateStatsStmt *stmt)
 	 * than the underlying table(s).
 	 */
 	ObjectAddressSet(parentobject, NamespaceRelationId, namespaceId);
+	LockNotPinnedObject(NamespaceRelationId, namespaceId);
 	recordDependencyOn(&myself, &parentobject, DEPENDENCY_NORMAL);
 
 	recordDependencyOnOwner(StatisticExtRelationId, statoid, stxowner);
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 66cda26a25..c66f110984 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -3438,6 +3438,7 @@ StoreCatalogInheritance1(Oid relationId, Oid parentOid,
 	childobject.objectId = relationId;
 	childobject.objectSubId = 0;
 
+	/* XXX Do we need a lock for RelationRelationId? */
 	recordDependencyOn(&childobject, &parentobject,
 					   child_dependency_type(child_is_partition));
 
@@ -7349,7 +7350,9 @@ ATExecAddColumn(List **wqueue, AlteredTableInfo *tab, Relation rel,
 	/*
 	 * Add needed dependency entries for the new column.
 	 */
+	LockNotPinnedObject(TypeRelationId, attribute->atttypid);
 	add_column_datatype_dependency(myrelid, newattnum, attribute->atttypid);
+	LockNotPinnedObject(CollationRelationId, attribute->attcollation);
 	add_column_collation_dependency(myrelid, newattnum, attribute->attcollation);
 
 	/*
@@ -10174,6 +10177,7 @@ addFkRecurseReferenced(List **wqueue, Constraint *fkconstraint, Relation rel,
 		ObjectAddress referenced;
 
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+		LockNotPinnedObject(ConstraintRelationId, parentConstr);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_INTERNAL);
 	}
 
@@ -10465,8 +10469,10 @@ addFkRecurseReferencing(List **wqueue, Constraint *fkconstraint, Relation rel,
 			 */
 			ObjectAddressSet(address, ConstraintRelationId, constrOid);
 			ObjectAddressSet(referenced, ConstraintRelationId, parentConstr);
+			LockNotPinnedObject(ConstraintRelationId, parentConstr);
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, partitionId);
+			/* XXX Do we need a lock for RelationRelationId? */
 			recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 			/* Make all this visible before recursing */
@@ -10967,9 +10973,11 @@ CloneFkReferencing(List **wqueue, Relation parentRel, Relation partRel)
 		/* Set up partition dependencies for the new constraint */
 		ObjectAddressSet(address, ConstraintRelationId, constrOid);
 		ObjectAddressSet(referenced, ConstraintRelationId, parentConstrOid);
+		LockDatabaseObject(ConstraintRelationId, parentConstrOid, 0, AccessShareLock);
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_PRI);
 		ObjectAddressSet(referenced, RelationRelationId,
 						 RelationGetRelid(partRel));
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&address, &referenced, DEPENDENCY_PARTITION_SEC);
 
 		/* Done with the cloned constraint's tuple */
@@ -13254,7 +13262,9 @@ ATExecAlterColumnType(AlteredTableInfo *tab, Relation rel,
 	table_close(attrelation, RowExclusiveLock);
 
 	/* Install dependencies on new datatype and collation */
+	LockNotPinnedObject(TypeRelationId, targettype);
 	add_column_datatype_dependency(RelationGetRelid(rel), attnum, targettype);
+	LockNotPinnedObject(CollationRelationId, targetcollid);
 	add_column_collation_dependency(RelationGetRelid(rel), attnum, targetcollid);
 
 	/*
@@ -14816,6 +14826,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 		 */
 		ObjectAddressSet(relobj, RelationRelationId, reloid);
 		ObjectAddressSet(referenced, AccessMethodRelationId, rd_rel->relam);
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		recordDependencyOn(&relobj, &referenced, DEPENDENCY_NORMAL);
 	}
 	else if (OidIsValid(oldAccessMethodId) &&
@@ -14835,6 +14846,7 @@ ATExecSetAccessMethodNoStorage(Relation rel, Oid newAccessMethodId)
 			   OidIsValid(rd_rel->relam));
 
 		/* Both are valid, so update the dependency */
+		LockNotPinnedObject(AccessMethodRelationId, rd_rel->relam);
 		changeDependencyFor(RelationRelationId, reloid,
 							AccessMethodRelationId,
 							oldAccessMethodId, rd_rel->relam);
@@ -16434,6 +16446,7 @@ ATExecAddOf(Relation rel, const TypeName *ofTypename, LOCKMODE lockmode)
 	typeobj.classId = TypeRelationId;
 	typeobj.objectId = typeid;
 	typeobj.objectSubId = 0;
+	LockNotPinnedObject(TypeRelationId, typeid);
 	recordDependencyOn(&tableobj, &typeobj, DEPENDENCY_NORMAL);
 
 	/* Update pg_class.reloftype */
@@ -17192,14 +17205,17 @@ AlterRelationNamespaceInternal(Relation classRel, Oid relOid,
 		CatalogTupleUpdate(classRel, &classTup->t_self, classTup);
 
 		/* Update dependency on schema if caller said so */
-		if (hasDependEntry &&
-			changeDependencyFor(RelationRelationId,
-								relOid,
-								NamespaceRelationId,
-								oldNspOid,
-								newNspOid) != 1)
-			elog(ERROR, "could not change schema dependency for relation \"%s\"",
-				 NameStr(classForm->relname));
+		if (hasDependEntry)
+		{
+			LockNotPinnedObject(NamespaceRelationId, newNspOid);
+			if (changeDependencyFor(RelationRelationId,
+									relOid,
+									NamespaceRelationId,
+									oldNspOid,
+									newNspOid) != 1)
+				elog(ERROR, "could not change schema dependency for relation \"%s\"",
+					 NameStr(classForm->relname));
+		}
 	}
 	if (!already_done)
 	{
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index 95de402fa6..44b15349b3 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -1018,8 +1018,6 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		((Form_pg_class) GETSTRUCT(tuple))->relhastriggers = true;
 
 		CatalogTupleUpdate(pgrel, &tuple->t_self, tuple);
-
-		CommandCounterIncrement();
 	}
 	else
 		CacheInvalidateRelcacheByTuple(tuple);
@@ -1027,6 +1025,12 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	heap_freetuple(tuple);
 	table_close(pgrel, RowExclusiveLock);
 
+	/*
+	 * CommandCounterIncrement here to ensure the new trigger entry is visible
+	 * when we'll check of object existence when recording the dependencies.
+	 */
+	CommandCounterIncrement();
+
 	/*
 	 * If we're replacing a trigger, flush all the old dependencies before
 	 * recording new ones.
@@ -1045,6 +1049,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 	referenced.classId = ProcedureRelationId;
 	referenced.objectId = funcoid;
 	referenced.objectSubId = 0;
+	LockNotPinnedObject(ProcedureRelationId, funcoid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 
 	if (isInternal && OidIsValid(constraintOid))
@@ -1058,6 +1063,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = ConstraintRelationId;
 		referenced.objectId = constraintOid;
 		referenced.objectSubId = 0;
+		LockNotPinnedObject(ConstraintRelationId, constraintOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 	else
@@ -1070,6 +1076,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		referenced.classId = RelationRelationId;
 		referenced.objectId = RelationGetRelid(rel);
 		referenced.objectSubId = 0;
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 
 		if (OidIsValid(constrrelid))
@@ -1077,6 +1084,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = RelationRelationId;
 			referenced.objectId = constrrelid;
 			referenced.objectSubId = 0;
+			/* XXX Do we need a lock for RelationRelationId? */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_AUTO);
 		}
 		/* Not possible to have an index dependency in this case */
@@ -1091,6 +1099,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 			referenced.classId = ConstraintRelationId;
 			referenced.objectId = constraintOid;
 			referenced.objectSubId = 0;
+			LockNotPinnedObject(TriggerRelationId, trigoid);
 			recordDependencyOn(&referenced, &myself, DEPENDENCY_INTERNAL);
 		}
 
@@ -1100,8 +1109,10 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		if (OidIsValid(parentTriggerOid))
 		{
 			ObjectAddressSet(referenced, TriggerRelationId, parentTriggerOid);
+			LockNotPinnedObject(TriggerRelationId, parentTriggerOid);
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_PRI);
 			ObjectAddressSet(referenced, RelationRelationId, RelationGetRelid(rel));
+			/* XXX Do we need a lock for RelationRelationId? */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_PARTITION_SEC);
 		}
 	}
@@ -1116,6 +1127,7 @@ CreateTriggerFiringOn(CreateTrigStmt *stmt, const char *queryString,
 		for (i = 0; i < ncolumns; i++)
 		{
 			referenced.objectSubId = columns[i];
+			/* XXX Do we need a lock for RelationRelationId? */
 			recordDependencyOn(&myself, &referenced, DEPENDENCY_NORMAL);
 		}
 	}
@@ -1255,9 +1267,11 @@ TriggerSetParentTrigger(Relation trigRel,
 		ObjectAddressSet(depender, TriggerRelationId, childTrigId);
 
 		ObjectAddressSet(referenced, TriggerRelationId, parentTrigId);
+		LockNotPinnedObject(TriggerRelationId, parentTrigId);
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_PRI);
 
 		ObjectAddressSet(referenced, RelationRelationId, childTableId);
+		/* XXX Do we need a lock for RelationRelationId? */
 		recordDependencyOn(&depender, &referenced, DEPENDENCY_PARTITION_SEC);
 	}
 	else
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index b7b5019f1e..29e02f4946 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -66,12 +66,12 @@ static DefElem *buildDefItem(const char *name, const char *val,
 /* --------------------- TS Parser commands ------------------------ */
 
 /*
- * lookup a parser support function and return its OID (as a Datum)
+ * lookup a parser support function and return its OID
  *
  * attnum is the pg_ts_parser column the function will go into
  */
-static Datum
-get_ts_parser_func(DefElem *defel, int attnum)
+static Oid
+get_ts_parser_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[3];
@@ -125,7 +125,7 @@ get_ts_parser_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -214,6 +214,7 @@ DefineTSParser(List *names, List *parameters)
 	namestrcpy(&pname, prsname);
 	values[Anum_pg_ts_parser_prsname - 1] = NameGetDatum(&pname);
 	values[Anum_pg_ts_parser_prsnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -224,28 +225,38 @@ DefineTSParser(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "start") == 0)
 		{
-			values[Anum_pg_ts_parser_prsstart - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsstart);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsstart);
+
+			values[Anum_pg_ts_parser_prsstart - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "gettoken") == 0)
 		{
-			values[Anum_pg_ts_parser_prstoken - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prstoken);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prstoken);
+
+			values[Anum_pg_ts_parser_prstoken - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "end") == 0)
 		{
-			values[Anum_pg_ts_parser_prsend - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsend);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsend);
+
+			values[Anum_pg_ts_parser_prsend - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "headline") == 0)
 		{
-			values[Anum_pg_ts_parser_prsheadline - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prsheadline);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prsheadline);
+
+			values[Anum_pg_ts_parser_prsheadline - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lextypes") == 0)
 		{
-			values[Anum_pg_ts_parser_prslextype - 1] =
-				get_ts_parser_func(defel, Anum_pg_ts_parser_prslextype);
+			Oid			procoid = get_ts_parser_func_oid(defel, Anum_pg_ts_parser_prslextype);
+
+			values[Anum_pg_ts_parser_prslextype - 1] = ObjectIdGetDatum(procoid);
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -474,6 +485,10 @@ DefineTSDictionary(List *names, List *parameters)
 
 	CatalogTupleInsert(dictRel, tup);
 
+	/* Lock objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSTemplateRelationId, templId);
+
 	address = makeDictionaryDependencies(tup);
 
 	/* Post creation hook for new text search dictionary */
@@ -601,12 +616,12 @@ AlterTSDictionary(AlterTSDictionaryStmt *stmt)
 /* ---------------------- TS Template commands -----------------------*/
 
 /*
- * lookup a template support function and return its OID (as a Datum)
+ * lookup a template support function and return its OID
  *
  * attnum is the pg_ts_template column the function will go into
  */
-static Datum
-get_ts_template_func(DefElem *defel, int attnum)
+static Oid
+get_ts_template_func_oid(DefElem *defel, int attnum)
 {
 	List	   *funcName = defGetQualifiedName(defel);
 	Oid			typeId[4];
@@ -642,7 +657,7 @@ get_ts_template_func(DefElem *defel, int attnum)
 						func_signature_string(funcName, nargs, NIL, typeId),
 						format_type_be(retTypeId))));
 
-	return ObjectIdGetDatum(procOid);
+	return procOid;
 }
 
 /*
@@ -723,6 +738,7 @@ DefineTSTemplate(List *names, List *parameters)
 	namestrcpy(&dname, tmplname);
 	values[Anum_pg_ts_template_tmplname - 1] = NameGetDatum(&dname);
 	values[Anum_pg_ts_template_tmplnamespace - 1] = ObjectIdGetDatum(namespaceoid);
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
 
 	/*
 	 * loop over the definition list and extract the information we need.
@@ -733,15 +749,19 @@ DefineTSTemplate(List *names, List *parameters)
 
 		if (strcmp(defel->defname, "init") == 0)
 		{
-			values[Anum_pg_ts_template_tmplinit - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmplinit);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmplinit);
+
+			values[Anum_pg_ts_template_tmplinit - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmplinit - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else if (strcmp(defel->defname, "lexize") == 0)
 		{
-			values[Anum_pg_ts_template_tmpllexize - 1] =
-				get_ts_template_func(defel, Anum_pg_ts_template_tmpllexize);
+			Oid			procoid = get_ts_template_func_oid(defel, Anum_pg_ts_template_tmpllexize);
+
+			values[Anum_pg_ts_template_tmpllexize - 1] = ObjectIdGetDatum(procoid);
 			nulls[Anum_pg_ts_template_tmpllexize - 1] = false;
+			LockNotPinnedObject(ProcedureRelationId, procoid);
 		}
 		else
 			ereport(ERROR,
@@ -879,6 +899,7 @@ makeConfigurationDependencies(HeapTuple tuple, bool removeOld,
 			referenced.objectId = cfgmap->mapdict;
 			referenced.objectSubId = 0;
 			add_exact_object_address(&referenced, addrs);
+			LockNotPinnedObject(TSDictionaryRelationId, cfgmap->mapdict);
 		}
 
 		systable_endscan(scan);
@@ -998,6 +1019,10 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	values[Anum_pg_ts_config_cfgowner - 1] = ObjectIdGetDatum(GetUserId());
 	values[Anum_pg_ts_config_cfgparser - 1] = ObjectIdGetDatum(prsOid);
 
+	/* Lock objects */
+	LockNotPinnedObject(NamespaceRelationId, namespaceoid);
+	LockNotPinnedObject(TSParserRelationId, prsOid);
+
 	tup = heap_form_tuple(cfgRel->rd_att, values, nulls);
 
 	CatalogTupleInsert(cfgRel, tup);
@@ -1156,6 +1181,7 @@ ObjectAddress
 AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 {
 	HeapTuple	tup;
+	Form_pg_ts_config cfg;
 	Oid			cfgId;
 	Relation	relMap;
 	ObjectAddress address;
@@ -1168,7 +1194,8 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 				 errmsg("text search configuration \"%s\" does not exist",
 						NameListToString(stmt->cfgname))));
 
-	cfgId = ((Form_pg_ts_config) GETSTRUCT(tup))->oid;
+	cfg = (Form_pg_ts_config) GETSTRUCT(tup);
+	cfgId = cfg->oid;
 
 	/* must be owner */
 	if (!object_ownercheck(TSConfigRelationId, cfgId, GetUserId()))
@@ -1183,6 +1210,10 @@ AlterTSConfiguration(AlterTSConfigurationStmt *stmt)
 	else if (stmt->tokentype)
 		DropConfigurationMapping(stmt, tup, relMap);
 
+	/* Lock dependent objects */
+	LockNotPinnedObject(NamespaceRelationId, cfg->cfgnamespace);
+	LockNotPinnedObject(TSParserRelationId, cfg->cfgparser);
+
 	/* Update dependencies */
 	makeConfigurationDependencies(tup, true, relMap);
 
@@ -1414,6 +1445,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				repl_val[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictNew);
 				repl_repl[Anum_pg_ts_config_map_mapdict - 1] = true;
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictNew);
+
 				newtup = heap_modify_tuple(maptup,
 										   RelationGetDescr(relMap),
 										   repl_val, repl_null, repl_repl);
@@ -1456,6 +1489,8 @@ MakeConfigurationMapping(AlterTSConfigurationStmt *stmt,
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapseqno - 1] = Int32GetDatum(j + 1);
 				slot[slotCount]->tts_values[Anum_pg_ts_config_map_mapdict - 1] = ObjectIdGetDatum(dictIds[j]);
 
+				LockNotPinnedObject(TSDictionaryRelationId, dictIds[j]);
+
 				ExecStoreVirtualTuple(slot[slotCount]);
 				slotCount++;
 
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index 2a1e713335..9febaa24a7 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -1794,6 +1794,7 @@ makeRangeConstructors(const char *name, Oid namespace,
 		 * that they go away silently when the type is dropped.  Note that
 		 * pg_dump depends on this choice to avoid dumping the constructors.
 		 */
+		LockNotPinnedObject(TypeRelationId, rangeOid);
 		recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	}
 }
@@ -1859,6 +1860,7 @@ makeMultirangeConstructors(const char *name, Oid namespace,
 	 * that they go away silently when the type is dropped.  Note that pg_dump
 	 * depends on this choice to avoid dumping the constructors.
 	 */
+	LockNotPinnedObject(TypeRelationId, multirangeOid);
 	recordDependencyOn(&myself, &referenced, DEPENDENCY_INTERNAL);
 	pfree(argtypes);
 
@@ -2672,6 +2674,45 @@ AlterDomainDefault(List *names, Node *defaultRaw)
 
 	CatalogTupleUpdate(rel, &tup->t_self, newtuple);
 
+	/* Lock dependent objects */
+	typTup = (Form_pg_type) GETSTRUCT(newtuple);
+
+	if (OidIsValid(typTup->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typTup->typnamespace);
+
+	if (OidIsValid(typTup->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typinput);
+
+	if (OidIsValid(typTup->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typoutput);
+
+	if (OidIsValid(typTup->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typreceive);
+
+	if (OidIsValid(typTup->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsend);
+
+	if (OidIsValid(typTup->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodin);
+
+	if (OidIsValid(typTup->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typmodout);
+
+	if (OidIsValid(typTup->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typanalyze);
+
+	if (OidIsValid(typTup->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typTup->typsubscript);
+
+	if (OidIsValid(typTup->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typTup->typbasetype);
+
+	if (OidIsValid(typTup->typcollation))
+		LockNotPinnedObject(CollationRelationId, typTup->typcollation);
+
+	if (OidIsValid(typTup->typelem))
+		LockNotPinnedObject(TypeRelationId, typTup->typelem);
+
 	/* Rebuild dependencies */
 	GenerateTypeDependencies(newtuple,
 							 rel,
@@ -4276,10 +4317,13 @@ AlterTypeNamespaceInternal(Oid typeOid, Oid nspOid,
 	if (oldNspOid != nspOid &&
 		(isCompositeType || typform->typtype != TYPTYPE_COMPOSITE) &&
 		!isImplicitArray)
+	{
+		LockNotPinnedObject(NamespaceRelationId, nspOid);
 		if (changeDependencyFor(TypeRelationId, typeOid,
 								NamespaceRelationId, oldNspOid, nspOid) != 1)
 			elog(ERROR, "could not change schema dependency for type \"%s\"",
 				 format_type_be(typeOid));
+	}
 
 	InvokeObjectPostAlterHook(TypeRelationId, typeOid, 0);
 
@@ -4571,6 +4615,7 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	SysScanDesc scan;
 	ScanKeyData key[1];
 	HeapTuple	domainTup;
+	Form_pg_type typeForm;
 
 	/* Since this function recurses, it could be driven to stack overflow */
 	check_stack_depth();
@@ -4619,6 +4664,45 @@ AlterTypeRecurse(Oid typeOid, bool isImplicitArray,
 	newtup = heap_modify_tuple(tup, RelationGetDescr(catalog),
 							   values, nulls, replaces);
 
+	/* Lock dependent objects */
+	typeForm = (Form_pg_type) GETSTRUCT(newtup);
+
+	if (OidIsValid(typeForm->typnamespace))
+		LockNotPinnedObject(NamespaceRelationId, typeForm->typnamespace);
+
+	if (OidIsValid(typeForm->typinput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typinput);
+
+	if (OidIsValid(typeForm->typoutput))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typoutput);
+
+	if (OidIsValid(typeForm->typreceive))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typreceive);
+
+	if (OidIsValid(typeForm->typsend))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsend);
+
+	if (OidIsValid(typeForm->typmodin))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodin);
+
+	if (OidIsValid(typeForm->typmodout))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typmodout);
+
+	if (OidIsValid(typeForm->typanalyze))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typanalyze);
+
+	if (OidIsValid(typeForm->typsubscript))
+		LockNotPinnedObject(ProcedureRelationId, typeForm->typsubscript);
+
+	if (OidIsValid(typeForm->typbasetype))
+		LockNotPinnedObject(TypeRelationId, typeForm->typbasetype);
+
+	if (OidIsValid(typeForm->typcollation))
+		LockNotPinnedObject(CollationRelationId, typeForm->typcollation);
+
+	if (OidIsValid(typeForm->typelem))
+		LockNotPinnedObject(TypeRelationId, typeForm->typelem);
+
 	CatalogTupleUpdate(catalog, &newtup->t_self, newtup);
 
 	/* Rebuild dependencies for this type */
diff --git a/src/backend/rewrite/rewriteDefine.c b/src/backend/rewrite/rewriteDefine.c
index 6cc9a8d8bf..ccd03ceeb8 100644
--- a/src/backend/rewrite/rewriteDefine.c
+++ b/src/backend/rewrite/rewriteDefine.c
@@ -155,6 +155,7 @@ InsertRule(const char *rulname,
 	referenced.objectId = eventrel_oid;
 	referenced.objectSubId = 0;
 
+	/* XXX Do we need a lock for RelationRelationId? */
 	recordDependencyOn(&myself, &referenced,
 					   (evtype == CMD_SELECT) ? DEPENDENCY_INTERNAL : DEPENDENCY_AUTO);
 
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1..60e8539fe3 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 7eee66f810..c57204cc40 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,9 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObjectById(const ObjectAddress *object);
+extern void LockNotPinnedObjectsById(const ObjectAddress *object, int nobject);
+extern void LockNotPinnedObject(Oid classid, Oid objid);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
@@ -128,6 +131,9 @@ extern void add_exact_object_address(const ObjectAddress *object,
 extern bool object_address_present(const ObjectAddress *object,
 								   const ObjectAddresses *addrs);
 
+extern void lock_record_object_address_dependencies(const ObjectAddress *depender,
+													ObjectAddresses *referenced,
+													DependencyType behavior);
 extern void record_object_address_dependencies(const ObjectAddress *depender,
 											   ObjectAddresses *referenced,
 											   DependencyType behavior);
@@ -172,6 +178,7 @@ extern long changeDependenciesOf(Oid classId, Oid oldObjectId,
 extern long changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
 								 Oid newRefObjectId);
 
+extern bool isObjectPinned(const ObjectAddress *object);
 extern Oid	getExtensionOfObject(Oid classId, Oid objectId);
 extern List *getAutoExtensionsOfObject(Oid classId, Oid objectId);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..56f746264b 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 0342eb39e4..1b67f0bffe 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -114,3 +114,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2025-05-19 17:02                                     ` Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2025-05-19 17:02 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Wed, 2024-05-22 at 10:48 -0400, Robert Haas wrote:
> > Then, Tom proposed another approach in [2] which is that "creation
> > DDL will have
> > to take a lock on each referenced object that'd conflict with a
> > lock taken by DROP".
> > This is the one the current patch is trying to implement.
> 
> It's a clever idea, but I'm not sure that I like it.

I'm not sure if you intended it this way, but using "clever" here
suggests that it's an unusual trick. But isn't that the kind of thing
heavyweight locks are for?

> 
> My concern was really more about the maintainability of
> the code. I fear that if we add code that takes heavyweight locks in
> surprising places, we might later find the behavior difficult to
> reason about.

FWIW, a lock while recording a dependency would not be surprising to
me. Assuming that heavyweight locks are the right approach, the locks
need to be taken somewhere. And expecting all the callers to get it
right seems error-prone.

This is a long thread so I must be missing some problem or complication
here.

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2025-05-19 18:07                                       ` Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Robert Haas @ 2025-05-19 18:07 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Mon, May 19, 2025 at 1:02 PM Jeff Davis <pgsql@j-davis.com> wrote:
> I'm not sure if you intended it this way, but using "clever" here
> suggests that it's an unusual trick. But isn't that the kind of thing
> heavyweight locks are for?
>
> FWIW, a lock while recording a dependency would not be surprising to
> me. Assuming that heavyweight locks are the right approach, the locks
> need to be taken somewhere. And expecting all the callers to get it
> right seems error-prone.

I agree with that, but I think that it may also be error-prone to
assume that it's OK to acquire heavyweight locks on other catalog
objects at any place in the code where we record a dependency. I will
not be surprised at all if that turns out to have some negative
consequences. For example, I think it might result in acquiring the
locks on those other objects at a subtly wrong time (leading to race
conditions) or acquiring two locks on the same object with different
lock modes where we should really only acquire one. I'm all in favor
of solving this problem using heavyweight locks, but I think that
implicitly acquiring them as a side effect of recording dependencies
feels too surprising.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2025-05-20 21:12                                         ` Jeff Davis <pgsql@j-davis.com>
  2025-05-21 06:37                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Jeff Davis @ 2025-05-20 21:12 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Mon, 2025-05-19 at 14:07 -0400, Robert Haas wrote:
> I agree with that, but I think that it may also be error-prone to
> assume that it's OK to acquire heavyweight locks on other catalog
> objects at any place in the code where we record a dependency. I will
> not be surprised at all if that turns out to have some negative
> consequences. For example, I think it might result in acquiring the
> locks on those other objects at a subtly wrong time (leading to race
> conditions) or acquiring two locks on the same object with different
> lock modes where we should really only acquire one. I'm all in favor
> of solving this problem using heavyweight locks, but I think that
> implicitly acquiring them as a side effect of recording dependencies
> feels too surprising.

I see what you mean now, in the sense that other code that calls
LockDatabaseObject (and other variants of LockAcquire) are mostly
higher-level operations like AlterPublication(), and not side-effects
of something else.

But relation_open() is sort of an exception. There are lots of places
where that takes a lock because we happen to want something out of the
relcache, like generate_partition_qual() taking a lock on the parent or
CheckAttributeType() taking a lock on the typrelid. You could say those
are fairly obvious, but that's because we already know, and we could
make it more widely known that recording a dependency takes a lock.

One compromise might be to have recordDependencyOn() take a LOCKMODE
parameter, which would both inform the caller that a lock will be
taken, and allow the caller to do it their own way and specify NoLock
if necessary. That still results in a huge diff, but the end result
would not be any more complex than the current code.

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2025-05-21 06:37                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2025-05-21 06:37 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Robert Haas <robertmhaas@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Tue, May 20, 2025 at 02:12:41PM -0700, Jeff Davis wrote:
> On Mon, 2025-05-19 at 14:07 -0400, Robert Haas wrote:
> > I agree with that, but I think that it may also be error-prone to
> > assume that it's OK to acquire heavyweight locks on other catalog
> > objects at any place in the code where we record a dependency. I will
> > not be surprised at all if that turns out to have some negative
> > consequences. For example, I think it might result in acquiring the
> > locks on those other objects at a subtly wrong time (leading to race
> > conditions) or acquiring two locks on the same object with different
> > lock modes where we should really only acquire one. I'm all in favor
> > of solving this problem using heavyweight locks, but I think that
> > implicitly acquiring them as a side effect of recording dependencies
> > feels too surprising.
> 
> I see what you mean now, in the sense that other code that calls
> LockDatabaseObject (and other variants of LockAcquire) are mostly
> higher-level operations like AlterPublication(), and not side-effects
> of something else.
> 
> But relation_open() is sort of an exception. There are lots of places
> where that takes a lock because we happen to want something out of the
> relcache, like generate_partition_qual() taking a lock on the parent or
> CheckAttributeType() taking a lock on the typrelid. You could say those
> are fairly obvious, but that's because we already know, and we could
> make it more widely known that recording a dependency takes a lock.
> 
> One compromise might be to have recordDependencyOn() take a LOCKMODE
> parameter, which would both inform the caller that a lock will be
> taken, and allow the caller to do it their own way and specify NoLock
> if necessary. That still results in a huge diff, but the end result
> would not be any more complex than the current code.

Thanks for sharing your thoughts! I had in mind to "just" check if there
is an existing lock (and if so, skip acquiring a new one) but your proposal
sounds better. Indeed it would make the locking behavior explicit and also
be flexible (allowing the callers to choose the LOCKMODE).

I'll prepare a new version implementing your proposal.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2025-05-21 16:55                                           ` Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Robert Haas @ 2025-05-21 16:55 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Tue, May 20, 2025 at 5:12 PM Jeff Davis <pgsql@j-davis.com> wrote:
> But relation_open() is sort of an exception. There are lots of places
> where that takes a lock because we happen to want something out of the
> relcache, like generate_partition_qual() taking a lock on the parent or
> CheckAttributeType() taking a lock on the typrelid. You could say those
> are fairly obvious, but that's because we already know, and we could
> make it more widely known that recording a dependency takes a lock.

To me, relation_open() feels like the kind of operation that I would
expect to take a lock. If I open something, I must have acquired some
resource on it that I will then use for a while before closing the
object.

> One compromise might be to have recordDependencyOn() take a LOCKMODE
> parameter, which would both inform the caller that a lock will be
> taken, and allow the caller to do it their own way and specify NoLock
> if necessary. That still results in a huge diff, but the end result
> would not be any more complex than the current code.

Yeah, that's not a terrible idea. I still like the idea I thought
Bertrand was pursuing, namely, to take no lock in recordDependencyOn()
but assert that the caller has previously acquired one. However, we
could still do the Assert() check with this design when NoLock is
passed, so I think this is a reasonable alternative to that design.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2025-05-21 17:17                                             ` Jeff Davis <pgsql@j-davis.com>
  2025-05-21 17:47                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Jeff Davis @ 2025-05-21 17:17 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Wed, 2025-05-21 at 12:55 -0400, Robert Haas wrote:
> > ...like generate_partition_qual() taking a lock on the parent or
> > CheckAttributeType() taking a lock on the typrelid...
> 
> To me, relation_open() feels like the kind of operation that I would
> expect to take a lock. If I open something, I must have acquired some
> resource on it that I will then use for a while before closing the
> object.

Of course relation_open() takes a lock, but sometimes relation_open()
is hidden in the call stack below other functions where it's not so
obvious.

> 
> Yeah, that's not a terrible idea. I still like the idea I thought
> Bertrand was pursuing, namely, to take no lock in
> recordDependencyOn()
> but assert that the caller has previously acquired one. However, we
> could still do the Assert() check with this design when NoLock is
> passed, so I think this is a reasonable alternative to that design.

I'd have to see the patch to see whether I liked the end result. But
I'm guessing that involves a lot of non-mechanical changes in the call
sites, and also relies on test coverage for all of them.

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2025-05-21 17:47                                               ` Robert Haas <robertmhaas@gmail.com>
  1 sibling, 0 replies; 93+ messages in thread

From: Robert Haas @ 2025-05-21 17:47 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Wed, May 21, 2025 at 1:18 PM Jeff Davis <pgsql@j-davis.com> wrote:
> Of course relation_open() takes a lock, but sometimes relation_open()
> is hidden in the call stack below other functions where it's not so
> obvious.

Probably true, although some of those are probably code that could
stand to be improved.

> > Yeah, that's not a terrible idea. I still like the idea I thought
> > Bertrand was pursuing, namely, to take no lock in
> > recordDependencyOn()
> > but assert that the caller has previously acquired one. However, we
> > could still do the Assert() check with this design when NoLock is
> > passed, so I think this is a reasonable alternative to that design.
>
> I'd have to see the patch to see whether I liked the end result. But
> I'm guessing that involves a lot of non-mechanical changes in the call
> sites, and also relies on test coverage for all of them.

Sure, fair enough.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2025-05-22 12:15                                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2025-05-22 12:15 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Robert Haas <robertmhaas@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, May 21, 2025 at 10:17:58AM -0700, Jeff Davis wrote:
> On Wed, 2025-05-21 at 12:55 -0400, Robert Haas wrote:
> > Yeah, that's not a terrible idea. I still like the idea I thought
> > Bertrand was pursuing, namely, to take no lock in
> > recordDependencyOn()
> > but assert that the caller has previously acquired one. However, we
> > could still do the Assert() check with this design when NoLock is
> > passed, so I think this is a reasonable alternative to that design.
> 
> I'd have to see the patch to see whether I liked the end result. But
> I'm guessing that involves a lot of non-mechanical changes in the call
> sites, and also relies on test coverage for all of them.

Thinking more about it, I'm not sure the NoLock/AccessShareLock will be easy
to make it right and maintain.

The thing is that in recordMultipleDependencies() we may iterate over multiple
referenced objects and those are the ones we want a lock on.

So if we enter recordMultipleDependencies() with "NoLock" we would need to be
100% sure that ALL the referenced objects are already locked (or that we don't
want to take a lock on ALL the referenced objects).

But that's not so easy, for example with something like:

create schema my_schema;
CREATE TABLE my_schema.test_maint(i INT);
INSERT INTO my_schema.test_maint VALUES (1), (2);
CREATE FUNCTION my_schema.fn(INT) RETURNS INT IMMUTABLE LANGUAGE plpgsql AS $$
  BEGIN
    RAISE NOTICE 'BDT';
    RETURN $1;
  END;
$$;

Then during:

CREATE MATERIALIZED VIEW my_schema.test_maint_mv AS SELECT my_schema.fn(i) FROM my_schema.test_maint;

1. The schema is locked
2. The relation is locked
3. The function is not locked

So we should pass "AccessShareLock" to recordMultipleDependencies() but that could
be easy to miss, resulting in passing "NoLock".

Furthermore, it means that even if we pass "AccessShareLock" correctly here, we'd
need to check that there is no existing lock on each referenced object (with
LockHeldByMe()/CheckRelationOidLockedByMe()) with a level > AccessShareLock (if
not, we'd add an extra lock without any good reason to do so).

With Robert's idea we could avoid to call LockDatabaseObject()/LockRelationOid()
if we know that the object/relation is already locked (or that we don't want 
a lock at this place). But it would mean being 100% sure that if there are
multiple code paths leading to the same referenced object insertion location
then each of them have the same locking behavior.

As that seems hard, a better approach would probably be to also always call
LockHeldByMe()/CheckRelationOidLockedByMe() before trying to acquire the lock.

So I think:

- Jeff's idea could be hard to reason about, as "NoLock" could mean: we are sure
that ALL the existing referenced objects are already locked and "AccessShareLock"
would mean: we know that at least one referenced object needs an AccessShareLock.
Then that would mean that "by design" we'd need to check if there is no existing
lock before trying to acquire the AccessShareLock on the referenced objects.

- Robert's idea would still require that we check whether there is any existing
lock before acquiring the AccessShareLock (to be on the safe side of things).

So I wonder if, after all, it makes sense to simply try to acquire the
AccessShareLock on a referenced object in recordMultipleDependencies() IIF
this referenced object is not already locked (basically what was initially
proposed, but with this extra check added and without the "NoLock"/"lock"
addition to recordMultipleDependencies())).

That would probably address Robert's concern [1] "acquiring two locks on the same
object with different lock modes where we should really only acquire one" but 
probably not this one "I think it might result in acquiring the
locks on those other objects at a subtly wrong time (leading to race
conditions)".

For the latter I'm not sure how that could be a subtly wrong time or how could
we determine what a subtly wrong time is (to avoid taking the lock).

Thoughts?

[1]: https://www.postgresql.org/message-id/CA%2BTgmoaCJ5-Zx5R0uN%2Bah4EZU1SamY1PneaW5O617FsNKavmfw%40mail...

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2025-05-22 13:40                                                 ` Robert Haas <robertmhaas@gmail.com>
  2025-05-22 19:38                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Robert Haas @ 2025-05-22 13:40 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Jeff Davis <pgsql@j-davis.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Thu, May 22, 2025 at 8:15 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> That would probably address Robert's concern [1] "acquiring two locks on the same
> object with different lock modes where we should really only acquire one" but
> probably not this one "I think it might result in acquiring the
> locks on those other objects at a subtly wrong time (leading to race
> conditions)".
>
> For the latter I'm not sure how that could be a subtly wrong time or how could
> we determine what a subtly wrong time is (to avoid taking the lock).

Well, I admit I'm not quite sure there is any timing problem here. But
I think it's possible. For example, consider RangeVarGetRelidExtended,
and in particular the callback argument. If we do permissions checking
before locking the relation, the results can change before we actually
lock the relation; if we do it afterward, users can contrive to hold
locks on relations for which they don't have permissions. That rather
ornate callback system allows us to have the best of both worlds. That
system is also concerned with the possibility that we do a name -> OID
translation before holding a lock and by the time we acquire the lock,
concurrent DDL has happened and the answer we got is no longer the
right answer. We've had security holes due to such things.

Now I'm not entirely sure that either of those things are issues here.
My first guess is that name lookup races are not an issue here,
because we're following OID links, but permissions checks seem like
they might be an issue. We might not decide to do something as
elaborate as we did with RangeVarGetRelidExtended and ... maybe that's
OK? But in general I am skeptical of the conclusion that we can just
shove all the locking down into some subordinate layer and nothing
will go wrong, because locking doesn't exist in a vacuum -- it relates
to other things that we also need to do, and whether we do the locking
before or after other steps can affect semantics and even security.

Pushing the locking down into recordDependencyOn amounts to hoping
that we don't need to study each code path in detail and decide on the
exactly right place to acquire the lock. It amounts to hoping that
wherever the recordDependencyOn call is located, it's before things
that we want the locking to happen before and after the things that we
want the locking to happen after. And maybe that's true. Or maybe it's
close enough to true that it's still better than the status quo where
we're not taking locks at all. But on the other hand, since I can't
think of any compelling reason why it HAS to be true, maybe it isn't.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2025-05-22 19:38                                                   ` Jeff Davis <pgsql@j-davis.com>
  2025-06-02 14:06                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2025-05-22 19:38 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Thu, 2025-05-22 at 09:40 -0400, Robert Haas wrote:

> Pushing the locking down into recordDependencyOn amounts to hoping
> that we don't need to study each code path in detail and decide on
> the
> exactly right place to acquire the lock.

There are (by my rough count) over 250 call sites modified by the v19
patch. I fear that, if each of those call sites needs to be studied for
the kinds of subtle issues you are describing, then we are likely to
make a mistake. If not now, then in the future as new features change
those call sites.

Bertrand, what pattern is safe to follow for most call sites? Which
call sites are the most interesting ones that need special attention?

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-22 19:38                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2025-06-02 14:06                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2025-06-02 14:06 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Robert Haas <robertmhaas@gmail.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, May 22, 2025 at 12:38:50PM -0700, Jeff Davis wrote:
> Which
> call sites are the most interesting ones that need special attention?

I think the ones that need special attention are the ones that check for
the permissions on the referenced objects *after* recordMultipleDependencies is
called (see [1]).

Does that make sense to you? 

[1]: https://www.postgresql.org/message-id/aD2u/GR/yaRkBJdJ%40ip-10-97-1-34.eu-west-3.compute.internal

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2025-06-02 14:02                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2025-06-02 14:02 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Jeff Davis <pgsql@j-davis.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, May 22, 2025 at 09:40:47AM -0400, Robert Haas wrote:
> On Thu, May 22, 2025 at 8:15 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > That would probably address Robert's concern [1] "acquiring two locks on the same
> > object with different lock modes where we should really only acquire one" but
> > probably not this one "I think it might result in acquiring the
> > locks on those other objects at a subtly wrong time (leading to race
> > conditions)".
> >
> > For the latter I'm not sure how that could be a subtly wrong time or how could
> > we determine what a subtly wrong time is (to avoid taking the lock).
> 
> Well, I admit I'm not quite sure there is any timing problem here. But
> I think it's possible. For example, consider RangeVarGetRelidExtended,
> and in particular the callback argument. If we do permissions checking
> before locking the relation, the results can change before we actually
> lock the relation; if we do it afterward, users can contrive to hold
> locks on relations for which they don't have permissions. That rather
> ornate callback system allows us to have the best of both worlds. That
> system is also concerned with the possibility that we do a name -> OID
> translation before holding a lock and by the time we acquire the lock,
> concurrent DDL has happened and the answer we got is no longer the
> right answer. We've had security holes due to such things.

Yeah I just looked at 2ad36c4e44c and see what issues it solved.

> 
> Now I'm not entirely sure that either of those things are issues here.
> My first guess is that name lookup races are not an issue here,
> because we're following OID links,

Yeah, I think the same and think that checking that the object(s) still exist
once we tried to get the lock is probably enough (as done in the patch versions
that have been shared).

> but permissions checks seem like
> they might be an issue.

I agree that we might end up locking an object we don't have the permission
on.

I just looked at 2 examples.

1.

CREATE MATERIALIZED VIEW test_maint_mv2 AS SELECT fn(i) FROM test_maint;

Would call recordMultipleDependencies() with the function as a referenced object:

Breakpoint 3, recordMultipleDependencies
123
(gdb) p *depender
$3 = {classId = 2618, objectId = 16468, objectSubId = 0}
(gdb) p *referenced
$4 = {classId = 1255, objectId = 16388, objectSubId = 0}

postgres=# select * from pg_identify_object(1255,16388,0);
   type   | schema | name |      identity
----------+--------+------+--------------------
 function | public |      | public.fn(integer)
(1 row)

But would check the permissions after:

Breakpoint 1, object_aclcheck (classid=1255, objectid=16388, roleid=16384, mode=128)
3823            return object_aclcheck_ext(classid, objectid, roleid, mode, NULL);

Means that in that case we'd put a lock on the function *before* checking for
the permissions.

2.

OTOH it's also possible the other way around:

CREATE FUNCTION myschema1.foo() RETURNS int AS 'select 1' LANGUAGE sql;

Would call object_aclcheck() on the schema:

Breakpoint 1, object_aclcheck (classid=2615, objectid=16435, roleid=10, mode=512)
3823            return object_aclcheck_ext(classid, objectid, roleid, mode, NULL);

postgres=# select * from pg_identify_object(2615,16435,0);
  type  | schema |   name    | identity
--------+--------+-----------+-----------
 schema |        | myschema1 | myschema1
(1 row)

before adding the dependency:

Breakpoint 3, recordMultipleDependencies
123
(gdb) p *referenced
$1 = {classId = 2615, objectId = 16435, objectSubId = 0}

> We might not decide to do something as
> elaborate as we did with RangeVarGetRelidExtended

So, we currently have 2 patterns:

P1: permission checks on a referenced object is done before we call recordMultipleDependencies()
P2: permission checks on a referenced object is done after we call recordMultipleDependencies()

So, if we add locking in recordMultipleDependencies() then I think that P2 is worst 
than P1 (there is still the risk that the permissions changed by the time
we reach recordMultipleDependencies() though).

As also stated in RangeVarGetRelidExtended()'s comment:

"
and it's really best to check permissions * before locking anything!
"

We could imagine doing the permissions check in recordMultipleDependencies() (in
more or less the same way as RangeVarGetRelidExtended() is doing with callback)
because only the recordMultipleDependencies()'s "caller" could know what kind of
check is needed. But that would not work for the same reasons as Jeff's proposal
does not fly (we may manipulate multiple referenced objects that would need
distinct callbacks...).

So, it looks like that we may need some refactoring of the existing code to
ensure that the permissions checks on the referenced objects are done before
the lock is acquired (before recordMultipleDependencies() is called?).

I propose to first try to list the cases where P2 is in action (and I think those
will be the ones that need special attention that Jeff is asking for in [1]).

And then discuss once we have the cases in hand. Thoughts?

[1]: https://www.postgresql.org/message-id/d721011cd3ec3aedd57b193ef10cf541f50df325.camel%40j-davis.com

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2025-06-03 17:27                                                     ` Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Robert Haas @ 2025-06-03 17:27 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Jeff Davis <pgsql@j-davis.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Mon, Jun 2, 2025 at 10:02 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> So, we currently have 2 patterns:
>
> P1: permission checks on a referenced object is done before we call recordMultipleDependencies()
> P2: permission checks on a referenced object is done after we call recordMultipleDependencies()
>
> So, if we add locking in recordMultipleDependencies() then I think that P2 is worst
> than P1 (there is still the risk that the permissions changed by the time
> we reach recordMultipleDependencies() though).

Hmm. I don't think I agree. If I understand correctly, P2 only permits
users to take a lock on an object they shouldn't be able to touch,
permitting them to temporarily interfere with access to it. P1 permits
users to potentially perform a permanent catalog modification that
should have been blocked by the permissions system. To my knowledge,
we've never formally classified the former type of problem as a
security vulnerability, although maybe there's an argument that it is
one. We've filed CVEs for problems of the latter sort.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2025-06-06 05:37                                                       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2025-06-06 05:37 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Jeff Davis <pgsql@j-davis.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Tue, Jun 03, 2025 at 01:27:29PM -0400, Robert Haas wrote:
> On Mon, Jun 2, 2025 at 10:02 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > So, we currently have 2 patterns:
> >
> > P1: permission checks on a referenced object is done before we call recordMultipleDependencies()
> > P2: permission checks on a referenced object is done after we call recordMultipleDependencies()
> >
> > So, if we add locking in recordMultipleDependencies() then I think that P2 is worst
> > than P1 (there is still the risk that the permissions changed by the time
> > we reach recordMultipleDependencies() though).
> 
> Hmm. I don't think I agree.

Thanks for sharing your thoughts!

> If I understand correctly, P2 only permits
> users to take a lock on an object they shouldn't be able to touch,
> permitting them to temporarily interfere with access to it. P1 permits
> users to potentially perform a permanent catalog modification that
> should have been blocked by the permissions system. To my knowledge,
> we've never formally classified the former type of problem as a
> security vulnerability, although maybe there's an argument that it is
> one. We've filed CVEs for problems of the latter sort.

What I meant to say is that P2 is worse "by design" because it's "always" wrong
to lock an object we don't have a permission on: so the permission should be
checked first.

So we have:

P1:

 * check_permissions()
 * permissions could change here
 * Lock in recordMultipleDependencies()

P2:

 * Lock in recordMultipleDependencies()
 * FWIW, permissions could change here too (for example, one could still "
revoke usage on schema myschema1 from user1" while there is an AccessShareLock
on schema myschema1)
 * check_permissions()

But P2 sequence of events is "wrong" by design (to lock an object we may not
have permissions on) that's what I meant.

Now if we look at it from a "pure" security angle (as you did) I agree that P1 is 
the worse because it could allow catalog change that should have been blocked by
the permission check.  P2 would prevent that. I agree that we should focus on
P1 then.

Let me try to list the P1 cases (instead of the P2 ones) so that we can focus on
/discuss those. 

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2025-11-09 08:33                                                         ` Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Roman Eskin @ 2025-11-09 08:33 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Robert Haas <robertmhaas@gmail.com>; +Cc: Jeff Davis <pgsql@j-davis.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi everybody,

Apologies for jumping into this conversation.

Our customers have also encountered a similar issue with the
concurrent drop of a dependent object. In our code (in the Greengage
DB), we implemented a fix analogous to one of the first versions of
Bertrand's approach, using locking within the pg_depend code.

In the long term, however, we are interested in aligning with the
upstream Postgres code as much as possible.

Since there haven't been any recent updates in this thread, we were
wondering if there are any plans for the next steps regarding this
issue.

Thank you in advance for your insights.

Best regards,
Roman Eskin

06.06.2025 15:37, Bertrand Drouvot пишет:
> Hi,
> 
> On Tue, Jun 03, 2025 at 01:27:29PM -0400, Robert Haas wrote:
>> On Mon, Jun 2, 2025 at 10:02 AM Bertrand Drouvot
>> <bertranddrouvot.pg@gmail.com> wrote:
>>> So, we currently have 2 patterns:
>>>
>>> P1: permission checks on a referenced object is done before we call recordMultipleDependencies()
>>> P2: permission checks on a referenced object is done after we call recordMultipleDependencies()
>>>
>>> So, if we add locking in recordMultipleDependencies() then I think that P2 is worst
>>> than P1 (there is still the risk that the permissions changed by the time
>>> we reach recordMultipleDependencies() though).
>>
>> Hmm. I don't think I agree.
> 
> Thanks for sharing your thoughts!
> 
>> If I understand correctly, P2 only permits
>> users to take a lock on an object they shouldn't be able to touch,
>> permitting them to temporarily interfere with access to it. P1 permits
>> users to potentially perform a permanent catalog modification that
>> should have been blocked by the permissions system. To my knowledge,
>> we've never formally classified the former type of problem as a
>> security vulnerability, although maybe there's an argument that it is
>> one. We've filed CVEs for problems of the latter sort.
> 
> What I meant to say is that P2 is worse "by design" because it's "always" wrong
> to lock an object we don't have a permission on: so the permission should be
> checked first.
> 
> So we have:
> 
> P1:
> 
>   * check_permissions()
>   * permissions could change here
>   * Lock in recordMultipleDependencies()
> 
> P2:
> 
>   * Lock in recordMultipleDependencies()
>   * FWIW, permissions could change here too (for example, one could still "
> revoke usage on schema myschema1 from user1" while there is an AccessShareLock
> on schema myschema1)
>   * check_permissions()
> 
> But P2 sequence of events is "wrong" by design (to lock an object we may not
> have permissions on) that's what I meant.
> 
> Now if we look at it from a "pure" security angle (as you did) I agree that P1 is
> the worse because it could allow catalog change that should have been blocked by
> the permission check.  P2 would prevent that. I agree that we should focus on
> P1 then.
> 
> Let me try to list the P1 cases (instead of the P2 ones) so that we can focus on
> /discuss those.
> 
> Regards,
> 

-- 
	С уважением,
Роман Ескин | C Developer
+7-964-449-81-15 | _r.eskin@arenadata.io_ <mailto:r.eskin@arenadata.io>
_Arenadata_ <https://arenadata.tech/> | Подписывайтесь на нас в Telegram
<https://t.me/arenadata; и VK <https://vk.com/arenadata;!

<https://arenadata.tech/events/;

УВЕДОМЛЕНИЕ О КОНФИДЕНЦИАЛЬНОСТИ:
Это электронное сообщение и любые документы, приложенные к нему, могут
содержать конфиденциальную информацию и предназначаются только
адресату/адресатам. Настоящим уведомляем Вас о том, что Вы не можете
воспроизводить, распространять и разглашать содержимое данного
электронного сообщения кому-либо без письменного согласия ООО «Аренадата
Софтвер». Разглашение конфиденциальной информации строго запрещено. Если
Вы получили это сообщение по ошибке, пожалуйста, сообщите об этом
отправителю по электронной почте и немедленно удалите это сообщение.







^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
@ 2026-04-15 18:36                                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-04-15 18:36 UTC (permalink / raw)
  To: Roman Eskin <r.eskin@arenadata.io>; +Cc: Robert Haas <robertmhaas@gmail.com>; Jeff Davis <pgsql@j-davis.com>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Sun, Nov 09, 2025 at 06:33:39PM +1000, Roman Eskin wrote:
> Hi everybody,
> 
> Apologies for jumping into this conversation.

No problem at all, you're more than welcome to join it!

> Our customers have also encountered a similar issue with the
> concurrent drop of a dependent object.

Yeah, it's not something so rare that one could thought (we also see a non
negligible of them in our fleet).

> In our code (in the Greengage
> DB), we implemented a fix analogous to one of the first versions of
> Bertrand's approach, using locking within the pg_depend code.
> 
> In the long term, however, we are interested in aligning with the
> upstream Postgres code as much as possible.
> 
> Since there haven't been any recent updates in this thread, we were
> wondering if there are any plans for the next steps regarding this
> issue.

Apologies for this late reply. I plan to work on this again in the coming weeks.
The next step I've in mind is to build the list of the P1 cases described above.

Once we've that list I think we could start discussing the next steps.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-04-28 11:17                                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-04-28 11:17 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; Jeff Davis <pgsql@j-davis.com>; Roman Eskin <r.eskin@arenadata.io>; +Cc: Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, Apr 15, 2026 at 06:36:49PM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Sun, Nov 09, 2025 at 06:33:39PM +1000, Roman Eskin wrote:
> > Hi everybody,
> > 
> > Apologies for jumping into this conversation.
> 
> No problem at all, you're more than welcome to join it!
> 
> > Our customers have also encountered a similar issue with the
> > concurrent drop of a dependent object.
> 
> Yeah, it's not something so rare that one could thought (we also see a non
> negligible of them in our fleet).
> 
> > In our code (in the Greengage
> > DB), we implemented a fix analogous to one of the first versions of
> > Bertrand's approach, using locking within the pg_depend code.
> > 
> > In the long term, however, we are interested in aligning with the
> > upstream Postgres code as much as possible.
> > 
> > Since there haven't been any recent updates in this thread, we were
> > wondering if there are any plans for the next steps regarding this
> > issue.
> 
> Apologies for this late reply. I plan to work on this again in the coming weeks.
> The next step I've in mind is to build the list of the P1 cases described above.
> 
> Once we've that list I think we could start discussing the next steps.

I've been able to identify the P1 cases (lock after acl check) thanks to 0003
attached (more on that later). With the list at hands, v20 attached is made of
3 sub patches.

0001: Avoid orphaned objects dependencies

Fix by acquiring AccessShareLock on referenced objects when recording
dependencies. This conflicts with AccessExclusiveLock taken by DROP,
preventing the race. After acquiring the lock, verify the object still
exists, if it was dropped concurrently, report an error.

The lock and check is done in both recordMultipleDependencies() and
changeDependencyFor().

Remarks:

1/ If the caller already holds a lock that conflicts with DROP (AccessShareLock
or stronger), skip the lock acquisition entirely.

2/ That does not address Robert's concern about lock after acl check cases and
that's what 0002 and 0003 are for.

0002: Lock referenced objects before permission checks in DDL commands

Add LockNotPinnedObjectById() calls before object_aclcheck() at all caller
sites where a permission check on a referenced object occurs before the
dependency on that object is recorded. This converts permission check before
lock to lock before permission check. It closes the TOCTOU window that could
allow a REVOKE to succeed between the permission check and the dependency
recording.

Note that the permission check before lock cases fixed in 0002 are already present.
0001 just makes the TOCTOU window wider in case there is a concurrent drop that
would block the dependency recording. So, I think that 0002 has merit on its own.

0003: Add Assert guard to detect permission check before lock regressions

Add instrumentation under USE_ASSERT_CHECKING to detect cases where object_aclcheck()
is called on a referenced object before a lock is held on it, which would widen
the TOCTOU window between the permission check and the dependency recording.

In recordMultipleDependencies() and changeDependencyFor(), for each referenced
object that had a permission check earlier in the same statement, assert that a
lock is already held. This catches any future code that adds a permission check
on a referenced object without first acquiring a lock.

This is enabled only for Assert enabled builds so that there is no overhead
for production builds.

I think that v20 is taking care of what has been discussed in this thread, mainly:

- It adds the new lock when the dependency is being recorded and thus avoids
having to modify about 250 call sites (as mentioned by Jeff in [1]).
- It addresses Robert's concern about the permission check before lock TOCTOU
window (thanks to 0002 that modifies about 70 call sites and 0003 that ensures
that we should trap new ones if any).

Thoughts?

[1]: https://postgr.es/m/d721011cd3ec3aedd57b193ef10cf541f50df325.camel%40j-davis.com

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v20-0001-Avoid-orphaned-objects-dependencies.patch (22.7K, ../../afCXPVNuvpf5ECGZ@bdtpg/2-v20-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 127b0c490c25c4c900543ec7b0e3261e1f7749b8 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Mon, 27 Apr 2026 14:01:46 +0000
Subject: [PATCH v20 1/3] Avoid orphaned objects dependencies

Concurrent DDL can create orphaned dependencies in pg_depend, objects
referencing other objects that no longer exist. For example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

Fix by acquiring AccessShareLock on referenced objects when recording
dependencies. This conflicts with AccessExclusiveLock taken by DROP,
preventing the race. After acquiring the lock, verify the object still
exists, if it was dropped concurrently, report an error.

The lock and check is done in both recordMultipleDependencies() and
changeDependencyFor().

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by:
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/dependency.c              |  72 ++++++++++
 src/backend/catalog/objectaddress.c           |  65 +++++++++
 src/backend/catalog/pg_depend.c               |  16 ++-
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   2 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  96 +++++++++++++
 src/test/regress/expected/alter_table.out     |  11 +-
 10 files changed, 386 insertions(+), 8 deletions(-)
  26.4% src/backend/catalog/
  41.3% src/test/isolation/expected/
  27.7% src/test/isolation/specs/
   4.3% src/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index fdb8e67e1f5..7e26691393d 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -87,6 +87,7 @@
 #include "parser/parsetree.h"
 #include "rewrite/rewriteRemove.h"
 #include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
@@ -1606,6 +1607,77 @@ ReleaseDeletionLock(const ObjectAddress *object)
 							 AccessExclusiveLock);
 }
 
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ *
+ * If the caller already holds a lock that conflicts with DROP
+ * (AccessShareLock or stronger), skip the lock acquisition entirely.
+ */
+void
+LockNotPinnedObject(const ObjectAddress *object)
+{
+	if (isObjectPinned(object))
+		return;
+
+	if (object->classId == RelationRelationId)
+	{
+		/* skip shared relations as they are pinned */
+		if (IsSharedRelation(object->objectId))
+			return;
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+		return;
+	}
+	else
+	{
+		LOCKTAG		tag;
+
+		SET_LOCKTAG_OBJECT(tag,
+						   MyDatabaseId,
+						   object->classId,
+						   object->objectId,
+						   0);
+
+		if (LockHeldByMe(&tag, AccessShareLock, true))
+			return;
+
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it (for example creating
+		 * a composite type while creating a relation), so bypass the syscache
+		 * lookup and use a SnapshotSelf scan instead to cover this scenario.
+		 */
+		if (!ObjectByIdExist(object, true))
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("dependent object does not exist"),
+					 errdetail("Class OID is %u and object OID is %u",
+							   object->classId, object->objectId)));
+	}
+}
+
 /*
  * recordDependencyOnExpr - find expression dependencies
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index c1862809577..d1ed8188d93 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -90,6 +90,7 @@
 #include "utils/lsyscache.h"
 #include "utils/memutils.h"
 #include "utils/regproc.h"
+#include "utils/snapmgr.h"
 #include "utils/syscache.h"
 
 /*
@@ -2696,6 +2697,70 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * If use_snapshot_self is false, uses the syscache (which sees committed data).
+ * If use_snapshot_self is true, does a direct catalog scan with SnapshotSelf
+ * to also see objects created in the current transaction.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_snapshot_self)
+{
+	HeapTuple	tuple;
+	SysCacheIdentifier cache = SYSCACHEID_INVALID;
+
+	if (!use_snapshot_self)
+	{
+		const ObjectPropertyType *property;
+
+		property = get_object_property_data(address->classId);
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache != SYSCACHEID_INVALID)
+	{
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+			return false;
+
+		ReleaseSysCache(tuple);
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		Snapshot	snapshot;
+
+		if (use_snapshot_self)
+			snapshot = SnapshotSelf;
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId),
+								  true, snapshot, 1, skey);
+
+		tuple = systable_getnext(scan);
+
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return HeapTupleIsValid(tuple);
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 07c2d41c189..5618e3d26fa 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -33,8 +33,6 @@
 #include "utils/syscache.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
 
 /*
  * Record a dependency between 2 objects via their respective ObjectAddress.
@@ -109,6 +107,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency.
+		 */
+		LockNotPinnedObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
@@ -507,6 +511,12 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+	/*
+	 * Acquire a lock and check object still exists while changing the
+	 * dependency.
+	 */
+	LockNotPinnedObject(&objAddr);
+
 	depRel = table_open(DependRelationId, RowExclusiveLock);
 
 	/* There should be existing dependency record(s), so search. */
@@ -707,7 +717,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 5b25402ebbe..58b498f68fc 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -278,6 +278,7 @@ Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 
 Section: Class 2D - Invalid Transaction Termination
 
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 2f3c1eae3c7..fa508ea70c6 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,8 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObject(const ObjectAddress *object);
+extern bool isObjectPinned(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 1f965e1faef..960b7e4bfa6 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -54,6 +54,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_snapshot_self);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 00000000000..820680f5e16
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  dependent object does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 1578ba191c8..83f626d51b5 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -126,3 +126,4 @@ test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
 test: for-portion-of
+test: test_dependencies_locks
\ No newline at end of file
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 00000000000..ee4130b2dc4
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,96 @@
+# Test that concurrent DDL properly prevents orphaned dependencies.
+#
+# When session 1 creates an object that depends on a referenced object,
+# and session 2 concurrently drops that referenced object, the lock
+# acquired during dependency recording must prevent the drop or the
+# create must fail with "dependent object does not exist".
+
+setup
+{
+	CREATE SCHEMA testschema;
+	CREATE SCHEMA alterschema;
+	CREATE TYPE public.foo as enum ('one', 'two');
+	CREATE TYPE public.footab as enum ('three', 'four');
+	CREATE DOMAIN id AS int;
+	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+	DROP FUNCTION IF EXISTS testschema.foo();
+	DROP FUNCTION IF EXISTS fooargtype(num foo);
+	DROP FUNCTION IF EXISTS footrettype();
+	DROP FUNCTION IF EXISTS foofunc();
+	DROP FUNCTION IF EXISTS public.falter();
+	DROP FUNCTION IF EXISTS alterschema.falter();
+	DROP DOMAIN IF EXISTS idid;
+	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP TABLE IF EXISTS tabtype;
+	DROP SCHEMA IF EXISTS testschema;
+	DROP SCHEMA IF EXISTS alterschema;
+	DROP TYPE IF EXISTS public.foo;
+	DROP TYPE IF EXISTS public.footab;
+	DROP DOMAIN IF EXISTS id;
+	DROP FUNCTION IF EXISTS f();
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 6dd22be0e8d..b891d68d4a7 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2949,11 +2949,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

  [text/x-diff] v20-0002-Lock-referenced-objects-before-permission-checks.patch (33.2K, ../../afCXPVNuvpf5ECGZ@bdtpg/3-v20-0002-Lock-referenced-objects-before-permission-checks.patch)
  download | inline diff:
From ae0de41b0f159e27af4a9be1b42ab6e9d10bd1d6 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Mon, 27 Apr 2026 14:19:51 +0000
Subject: [PATCH v20 2/3] Lock referenced objects before permission checks in
 DDL commands

Add LockNotPinnedObjectById() calls before object_aclcheck() at all caller
sites where a permission check on a referenced object occurs before the
dependency on that object is recorded. This converts permission check before
lock to lock before permission check. It closes the TOCTOU window that could
allow a REVOKE to succeed between the permission check and the dependency
recording.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by:
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/dependency.c        | 22 ++++++++++++++++++++++
 src/backend/catalog/namespace.c         |  1 +
 src/backend/catalog/pg_aggregate.c      |  5 +++++
 src/backend/catalog/pg_cast.c           |  1 +
 src/backend/catalog/pg_operator.c       |  2 ++
 src/backend/commands/aggregatecmds.c    |  2 ++
 src/backend/commands/alter.c            |  3 +++
 src/backend/commands/collationcmds.c    |  2 ++
 src/backend/commands/conversioncmds.c   |  3 +++
 src/backend/commands/extension.c        |  1 +
 src/backend/commands/foreigncmds.c      |  5 +++++
 src/backend/commands/functioncmds.c     | 11 +++++++++++
 src/backend/commands/indexcmds.c        |  2 ++
 src/backend/commands/opclasscmds.c      |  2 ++
 src/backend/commands/operatorcmds.c     |  8 ++++++++
 src/backend/commands/statscmds.c        |  1 +
 src/backend/commands/subscriptioncmds.c |  4 ++++
 src/backend/commands/tablecmds.c        |  7 +++++++
 src/backend/commands/trigger.c          |  2 ++
 src/backend/commands/tsearchcmds.c      |  2 ++
 src/backend/commands/typecmds.c         |  8 ++++++++
 src/include/catalog/dependency.h        |  1 +
 22 files changed, 95 insertions(+)
  22.8% src/backend/catalog/
  75.8% src/backend/commands/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 7e26691393d..a41e6ee2175 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1678,6 +1678,24 @@ LockNotPinnedObject(const ObjectAddress *object)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object if it is not pinned.  This is a convenience wrapper
+ * for callers that need to lock a referenced object before a permission
+ * check, converting permission check before lock to lock before permission
+ * check.
+ */
+void
+LockNotPinnedObjectById(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObject(&object);
+}
+
 /*
  * recordDependencyOnExpr - find expression dependencies
  *
@@ -1960,8 +1978,11 @@ find_expr_references_walker(Node *node,
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(PROCOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObjectById(ProcedureRelationId, objoid);
 						add_object_address(ProcedureRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGOPEROID:
 				case REGOPERATOROID:
@@ -2057,6 +2078,7 @@ find_expr_references_walker(Node *node,
 	{
 		FuncExpr   *funcexpr = (FuncExpr *) node;
 
+		LockNotPinnedObjectById(ProcedureRelationId, funcexpr->funcid);
 		add_object_address(ProcedureRelationId, funcexpr->funcid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
diff --git a/src/backend/catalog/namespace.c b/src/backend/catalog/namespace.c
index 56b87d878e8..7dec076e111 100644
--- a/src/backend/catalog/namespace.c
+++ b/src/backend/catalog/namespace.c
@@ -3512,6 +3512,7 @@ LookupCreationNamespace(const char *nspname)
 
 	namespaceId = get_namespace_oid(nspname, false);
 
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 243b952b9cc..41b390e8d96 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -586,22 +586,26 @@ AggregateCreate(const char *aggName,
 	 */
 	for (i = 0; i < numArgs; i++)
 	{
+		LockNotPinnedObjectById(TypeRelationId, aggArgTypes[i]);
 		aclresult = object_aclcheck(TypeRelationId, aggArgTypes[i], GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, aggArgTypes[i]);
 	}
 
+	LockNotPinnedObjectById(TypeRelationId, aggTransType);
 	aclresult = object_aclcheck(TypeRelationId, aggTransType, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, aggTransType);
 
 	if (OidIsValid(aggmTransType))
 	{
+		LockNotPinnedObjectById(TypeRelationId, aggmTransType);
 		aclresult = object_aclcheck(TypeRelationId, aggmTransType, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, aggmTransType);
 	}
 
+	LockNotPinnedObjectById(TypeRelationId, finaltype);
 	aclresult = object_aclcheck(TypeRelationId, finaltype, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, finaltype);
@@ -909,6 +913,7 @@ lookup_agg_function(List *fnName,
 	}
 
 	/* Check aggregate creator has permission to call the function */
+	LockNotPinnedObjectById(ProcedureRelationId, fnOid);
 	aclresult = object_aclcheck(ProcedureRelationId, fnOid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION, get_func_name(fnOid));
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5119c2acda2..bb48e686f83 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -105,6 +105,7 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
+		LockNotPinnedObjectById(ProcedureRelationId, funcid);
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
 	}
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 6b90c774c18..a222358d081 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -654,6 +654,7 @@ get_other_operator(List *otherOp, Oid otherLeftTypeId, Oid otherRightTypeId,
 
 	/* not in catalogs, different from operator, so make shell */
 
+	LockNotPinnedObjectById(NamespaceRelationId, otherNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, otherNamespace, GetUserId(),
 								ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
@@ -876,6 +877,7 @@ makeOperatorDependencies(HeapTuple tuple,
 	/* Dependency on namespace */
 	if (OidIsValid(oper->oprnamespace))
 	{
+		LockNotPinnedObjectById(NamespaceRelationId, oper->oprnamespace);
 		ObjectAddressSet(referenced, NamespaceRelationId, oper->oprnamespace);
 		add_exact_object_address(&referenced, addrs);
 	}
diff --git a/src/backend/commands/aggregatecmds.c b/src/backend/commands/aggregatecmds.c
index 41b45dc6402..c2fb111daf3 100644
--- a/src/backend/commands/aggregatecmds.c
+++ b/src/backend/commands/aggregatecmds.c
@@ -22,6 +22,7 @@
  */
 #include "postgres.h"
 
+#include "catalog/dependency.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_aggregate.h"
 #include "catalog/pg_namespace.h"
@@ -101,6 +102,7 @@ DefineAggregate(ParseState *pstate,
 	aggNamespace = QualifiedNameGetCreationNamespace(name, &aggName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, aggNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, aggNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 74ceb5fe20d..03516cb0d2e 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -221,6 +221,7 @@ AlterObjectRename_internal(Relation rel, Oid objectId, const char *new_name)
 		/* User must have CREATE privilege on the namespace */
 		if (OidIsValid(namespaceId))
 		{
+			LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 			aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(),
 										ACL_CREATE);
 			if (aclresult != ACLCHECK_OK)
@@ -752,6 +753,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 						   NameStr(*(DatumGetName(name))));
 
 		/* User must have CREATE privilege on new namespace */
+		LockNotPinnedObjectById(NamespaceRelationId, nspOid);
 		aclresult = object_aclcheck(NamespaceRelationId, nspOid, GetUserId(), ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -1014,6 +1016,7 @@ AlterObjectOwner_internal(Oid classId, Oid objectId, Oid new_ownerId)
 			{
 				AclResult	aclresult;
 
+				LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 				aclresult = object_aclcheck(NamespaceRelationId, namespaceId, new_ownerId,
 											ACL_CREATE);
 				if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/collationcmds.c b/src/backend/commands/collationcmds.c
index 0bc31ec2b6f..fa5dad1aa1f 100644
--- a/src/backend/commands/collationcmds.c
+++ b/src/backend/commands/collationcmds.c
@@ -21,6 +21,7 @@
 #include "access/htup_details.h"
 #include "access/table.h"
 #include "access/xact.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/namespace.h"
 #include "catalog/objectaccess.h"
@@ -82,6 +83,7 @@ DefineCollation(ParseState *pstate, List *names, List *parameters, bool if_not_e
 
 	collNamespace = QualifiedNameGetCreationNamespace(names, &collName);
 
+	LockNotPinnedObjectById(NamespaceRelationId, collNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, collNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/commands/conversioncmds.c b/src/backend/commands/conversioncmds.c
index 5f2022d3072..d60ecdb711a 100644
--- a/src/backend/commands/conversioncmds.c
+++ b/src/backend/commands/conversioncmds.c
@@ -14,6 +14,7 @@
  */
 #include "postgres.h"
 
+#include "catalog/dependency.h"
 #include "catalog/pg_conversion.h"
 #include "catalog/pg_namespace.h"
 #include "catalog/pg_proc.h"
@@ -50,6 +51,7 @@ CreateConversionCommand(CreateConversionStmt *stmt)
 													&conversion_name);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -97,6 +99,7 @@ CreateConversionCommand(CreateConversionStmt *stmt)
 						NameListToString(func_name), "integer")));
 
 	/* Check we have EXECUTE rights for the function */
+	LockNotPinnedObjectById(ProcedureRelationId, funcoid);
 	aclresult = object_aclcheck(ProcedureRelationId, funcoid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION,
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index a330b5fd6ce..4e82a010788 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -3283,6 +3283,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 					   extensionName);
 
 	/* Permission check: must have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, nspOid);
 	aclresult = object_aclcheck(NamespaceRelationId, nspOid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA, newschema);
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index c4852be2eb2..dd31e260739 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -377,6 +377,7 @@ AlterForeignServerOwner_internal(Relation rel, HeapTuple tup, Oid newOwnerId)
 			check_can_set_role(GetUserId(), newOwnerId);
 
 			/* New owner must have USAGE privilege on foreign-data wrapper */
+			LockNotPinnedObjectById(ForeignDataWrapperRelationId, form->srvfdw);
 			aclresult = object_aclcheck(ForeignDataWrapperRelationId, form->srvfdw, newOwnerId, ACL_USAGE);
 			if (aclresult != ACLCHECK_OK)
 			{
@@ -997,6 +998,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	 */
 	fdw = GetForeignDataWrapperByName(stmt->fdwname, false);
 
+	LockNotPinnedObjectById(ForeignDataWrapperRelationId, fdw->fdwid);
 	aclresult = object_aclcheck(ForeignDataWrapperRelationId, fdw->fdwid, ownerId, ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FDW, fdw->fdwname);
@@ -1188,6 +1190,7 @@ user_mapping_ddl_aclcheck(Oid umuserid, Oid serverid, const char *servername)
 		{
 			AclResult	aclresult;
 
+			LockNotPinnedObjectById(ForeignServerRelationId, serverid);
 			aclresult = object_aclcheck(ForeignServerRelationId, serverid, curuserid, ACL_USAGE);
 			if (aclresult != ACLCHECK_OK)
 				aclcheck_error(aclresult, OBJECT_FOREIGN_SERVER, servername);
@@ -1539,6 +1542,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	 * get the actual FDW for option validation etc.
 	 */
 	server = GetForeignServerByName(stmt->servername, false);
+	LockNotPinnedObjectById(ForeignServerRelationId, server->serverid);
 	aclresult = object_aclcheck(ForeignServerRelationId, server->serverid, ownerId, ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FOREIGN_SERVER, server->servername);
@@ -1598,6 +1602,7 @@ ImportForeignSchema(ImportForeignSchemaStmt *stmt)
 
 	/* Check that the foreign server exists and that we have USAGE on it */
 	server = GetForeignServerByName(stmt->server_name, false);
+	LockNotPinnedObjectById(ForeignServerRelationId, server->serverid);
 	aclresult = object_aclcheck(ForeignServerRelationId, server->serverid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FOREIGN_SERVER, server->servername);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 3afd762e9dc..9aec534c390 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -146,6 +146,7 @@ compute_return_type(TypeName *returnType, Oid languageOid,
 				 errdetail("Creating a shell type definition.")));
 		namespaceId = QualifiedNameGetCreationNamespace(returnType->names,
 														&typname);
+		LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 		aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(),
 									ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
@@ -158,6 +159,7 @@ compute_return_type(TypeName *returnType, Oid languageOid,
 		CommandCounterIncrement();
 	}
 
+	LockNotPinnedObjectById(TypeRelationId, rettype);
 	aclresult = object_aclcheck(TypeRelationId, rettype, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, rettype);
@@ -274,6 +276,7 @@ interpret_function_parameter_list(ParseState *pstate,
 			toid = InvalidOid;	/* keep compiler quiet */
 		}
 
+		LockNotPinnedObjectById(TypeRelationId, toid);
 		aclresult = object_aclcheck(TypeRelationId, toid, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, toid);
@@ -1071,6 +1074,7 @@ CreateFunction(ParseState *pstate, CreateFunctionStmt *stmt)
 													&funcname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -1125,6 +1129,7 @@ CreateFunction(ParseState *pstate, CreateFunctionStmt *stmt)
 	if (languageStruct->lanpltrusted)
 	{
 		/* if trusted language, need USAGE privilege */
+		LockNotPinnedObjectById(LanguageRelationId, languageOid);
 		aclresult = object_aclcheck(LanguageRelationId, languageOid, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_LANGUAGE,
@@ -1582,10 +1587,12 @@ CreateCast(CreateCastStmt *stmt)
 						format_type_be(sourcetypeid),
 						format_type_be(targettypeid))));
 
+	LockNotPinnedObjectById(TypeRelationId, sourcetypeid);
 	aclresult = object_aclcheck(TypeRelationId, sourcetypeid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, sourcetypeid);
 
+	LockNotPinnedObjectById(TypeRelationId, targettypeid);
 	aclresult = object_aclcheck(TypeRelationId, targettypeid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, targettypeid);
@@ -1874,6 +1881,7 @@ CreateTransform(CreateTransformStmt *stmt)
 	if (!object_ownercheck(TypeRelationId, typeid, GetUserId()))
 		aclcheck_error_type(ACLCHECK_NOT_OWNER, typeid);
 
+	LockNotPinnedObjectById(TypeRelationId, typeid);
 	aclresult = object_aclcheck(TypeRelationId, typeid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, typeid);
@@ -1883,6 +1891,7 @@ CreateTransform(CreateTransformStmt *stmt)
 	 */
 	langid = get_language_oid(stmt->lang, false);
 
+	LockNotPinnedObjectById(LanguageRelationId, langid);
 	aclresult = object_aclcheck(LanguageRelationId, langid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_LANGUAGE, stmt->lang);
@@ -1897,6 +1906,7 @@ CreateTransform(CreateTransformStmt *stmt)
 		if (!object_ownercheck(ProcedureRelationId, fromsqlfuncid, GetUserId()))
 			aclcheck_error(ACLCHECK_NOT_OWNER, OBJECT_FUNCTION, NameListToString(stmt->fromsql->objname));
 
+		LockNotPinnedObjectById(ProcedureRelationId, fromsqlfuncid);
 		aclresult = object_aclcheck(ProcedureRelationId, fromsqlfuncid, GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_FUNCTION, NameListToString(stmt->fromsql->objname));
@@ -1923,6 +1933,7 @@ CreateTransform(CreateTransformStmt *stmt)
 		if (!object_ownercheck(ProcedureRelationId, tosqlfuncid, GetUserId()))
 			aclcheck_error(ACLCHECK_NOT_OWNER, OBJECT_FUNCTION, NameListToString(stmt->tosql->objname));
 
+		LockNotPinnedObjectById(ProcedureRelationId, tosqlfuncid);
 		aclresult = object_aclcheck(ProcedureRelationId, tosqlfuncid, GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_FUNCTION, NameListToString(stmt->tosql->objname));
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 9ab74c8df0a..6216ab2a5f5 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -25,6 +25,7 @@
 #include "access/tableam.h"
 #include "access/xact.h"
 #include "catalog/catalog.h"
+#include "catalog/dependency.h"
 #include "catalog/index.h"
 #include "catalog/indexing.h"
 #include "catalog/namespace.h"
@@ -770,6 +771,7 @@ DefineIndex(ParseState *pstate,
 	{
 		AclResult	aclresult;
 
+		LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 		aclresult = object_aclcheck(NamespaceRelationId, namespaceId, root_save_userid,
 									ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index 7493a9ccc06..ad71ee53cb2 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -363,6 +363,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 													 &opcname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceoid);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceoid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -801,6 +802,7 @@ DefineOpFamily(CreateOpFamilyStmt *stmt)
 													 &opfname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceoid);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceoid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 3e7b09b3494..bb2ce833bdd 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -92,6 +93,7 @@ DefineOperator(List *names, List *parameters)
 	oprNamespace = QualifiedNameGetCreationNamespace(names, &oprName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, oprNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, oprNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -189,6 +191,7 @@ DefineOperator(List *names, List *parameters)
 
 	if (typeName1)
 	{
+		LockNotPinnedObjectById(TypeRelationId, typeId1);
 		aclresult = object_aclcheck(TypeRelationId, typeId1, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, typeId1);
@@ -196,6 +199,7 @@ DefineOperator(List *names, List *parameters)
 
 	if (typeName2)
 	{
+		LockNotPinnedObjectById(TypeRelationId, typeId2);
 		aclresult = object_aclcheck(TypeRelationId, typeId2, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, typeId2);
@@ -227,12 +231,14 @@ DefineOperator(List *names, List *parameters)
 	 * necessary, since EXECUTE will be checked at any attempted use of the
 	 * operator, but it seems like a good idea anyway.
 	 */
+	LockNotPinnedObjectById(ProcedureRelationId, functionOid);
 	aclresult = object_aclcheck(ProcedureRelationId, functionOid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION,
 					   NameListToString(functionName));
 
 	rettype = get_func_rettype(functionOid);
+	LockNotPinnedObjectById(TypeRelationId, rettype);
 	aclresult = object_aclcheck(TypeRelationId, rettype, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, rettype);
@@ -312,6 +318,7 @@ ValidateRestrictionEstimator(List *restrictionName)
 	{
 		AclResult	aclresult;
 
+		LockNotPinnedObjectById(ProcedureRelationId, restrictionOid);
 		aclresult = object_aclcheck(ProcedureRelationId, restrictionOid,
 									GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
@@ -382,6 +389,7 @@ ValidateJoinEstimator(List *joinName)
 	{
 		AclResult	aclresult;
 
+		LockNotPinnedObjectById(ProcedureRelationId, joinOid);
 		aclresult = object_aclcheck(ProcedureRelationId, joinOid,
 									GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index b354723be44..6afef0f55c4 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -185,6 +185,7 @@ CreateStatistics(CreateStatsStmt *stmt, bool check_rights)
 	{
 		AclResult	aclresult;
 
+		LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 		aclresult = object_aclcheck(NamespaceRelationId, namespaceId,
 									GetUserId(), ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/subscriptioncmds.c b/src/backend/commands/subscriptioncmds.c
index 1e10d9d9a58..560f8bff629 100644
--- a/src/backend/commands/subscriptioncmds.c
+++ b/src/backend/commands/subscriptioncmds.c
@@ -745,6 +745,7 @@ CreateSubscription(ParseState *pstate, CreateSubscriptionStmt *stmt,
 		conninfo = NULL;
 
 		server = GetForeignServerByName(stmt->servername, false);
+		LockNotPinnedObjectById(ForeignServerRelationId, server->serverid);
 		aclresult = object_aclcheck(ForeignServerRelationId, server->serverid, owner, ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_FOREIGN_SERVER, server->servername);
@@ -1833,6 +1834,7 @@ AlterSubscription(ParseState *pstate, AlterSubscriptionStmt *stmt,
 				 * the server.
 				 */
 				new_server = GetForeignServerByName(stmt->servername, false);
+				LockNotPinnedObjectById(ForeignServerRelationId, new_server->serverid);
 				aclresult = object_aclcheck(ForeignServerRelationId,
 											new_server->serverid,
 											form->subowner, ACL_USAGE);
@@ -2253,6 +2255,7 @@ DropSubscription(DropSubscriptionStmt *stmt, bool isTopLevel)
 		ForeignServer *server;
 
 		server = GetForeignServer(form->subserver);
+		LockNotPinnedObjectById(ForeignServerRelationId, form->subserver);
 		aclresult = object_aclcheck(ForeignServerRelationId, form->subserver,
 									form->subowner, ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
@@ -2597,6 +2600,7 @@ AlterSubscriptionOwner_internal(Relation rel, HeapTuple tup, Oid newOwnerId)
 	{
 		ForeignServer *server = GetForeignServer(form->subserver);
 
+		LockNotPinnedObjectById(ForeignServerRelationId, server->serverid);
 		aclresult = object_aclcheck(ForeignServerRelationId, server->serverid, newOwnerId, ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			ereport(ERROR,
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index d8d7969bf30..decd5071ea6 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -30,6 +30,7 @@
 #include "access/xlog.h"
 #include "access/xloginsert.h"
 #include "catalog/catalog.h"
+#include "catalog/dependency.h"
 #include "catalog/heap.h"
 #include "catalog/index.h"
 #include "catalog/namespace.h"
@@ -997,6 +998,7 @@ DefineRelation(CreateStmt *stmt, char relkind, Oid ownerId,
 
 		ofTypeId = typenameTypeId(NULL, stmt->ofTypename);
 
+		LockNotPinnedObjectById(TypeRelationId, ofTypeId);
 		aclresult = object_aclcheck(TypeRelationId, ofTypeId, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, ofTypeId);
@@ -1462,6 +1464,7 @@ BuildDescForRelation(const List *columns)
 		attname = entry->colname;
 		typenameTypeIdAndMod(NULL, entry->typeName, &atttypid, &atttypmod);
 
+		LockNotPinnedObjectById(TypeRelationId, atttypid);
 		aclresult = object_aclcheck(TypeRelationId, atttypid, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, atttypid);
@@ -13941,6 +13944,7 @@ checkFkeyPermissions(Relation rel, int16 *attnums, int natts)
 	int			i;
 
 	/* Okay if we have relation-level REFERENCES permission */
+	LockNotPinnedObjectById(RelationRelationId, RelationGetRelid(rel));
 	aclresult = pg_class_aclcheck(RelationGetRelid(rel), roleid,
 								  ACL_REFERENCES);
 	if (aclresult == ACLCHECK_OK)
@@ -14724,6 +14728,7 @@ ATPrepAlterColumnType(List **wqueue,
 	/* Look up the target type */
 	typenameTypeIdAndMod(pstate, typeName, &targettype, &targettypmod);
 
+	LockNotPinnedObjectById(TypeRelationId, targettype);
 	aclresult = object_aclcheck(TypeRelationId, targettype, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, targettype);
@@ -16476,6 +16481,7 @@ ATExecChangeOwner(Oid relationOid, Oid newOwnerId, bool recursing, LOCKMODE lock
 				check_can_set_role(GetUserId(), newOwnerId);
 
 				/* New owner must have CREATE privilege on namespace */
+				LockNotPinnedObjectById(NamespaceRelationId, namespaceOid);
 				aclresult = object_aclcheck(NamespaceRelationId, namespaceOid, newOwnerId,
 											ACL_CREATE);
 				if (aclresult != ACLCHECK_OK)
@@ -19882,6 +19888,7 @@ RangeVarCallbackForAlterRelation(const RangeVar *rv, Oid relid, Oid oldrelid,
 	 */
 	if (IsA(stmt, RenameStmt))
 	{
+		LockNotPinnedObjectById(NamespaceRelationId, classform->relnamespace);
 		aclresult = object_aclcheck(NamespaceRelationId, classform->relnamespace,
 									GetUserId(), ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index da0d1ba6791..dab6067bbf9 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -350,6 +350,7 @@ CreateTriggerFiringOn(const CreateTrigStmt *stmt, const char *queryString,
 
 		if (OidIsValid(constrrelid))
 		{
+			LockNotPinnedObjectById(RelationRelationId, constrrelid);
 			aclresult = pg_class_aclcheck(constrrelid, GetUserId(),
 										  ACL_TRIGGER);
 			if (aclresult != ACLCHECK_OK)
@@ -695,6 +696,7 @@ CreateTriggerFiringOn(const CreateTrigStmt *stmt, const char *queryString,
 		funcoid = LookupFuncName(stmt->funcname, 0, NULL, false);
 	if (!isInternal)
 	{
+		LockNotPinnedObjectById(ProcedureRelationId, funcoid);
 		aclresult = object_aclcheck(ProcedureRelationId, funcoid, GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_FUNCTION,
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index a12ce33bae4..eb9e68bbb91 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -414,6 +414,7 @@ DefineTSDictionary(List *names, List *parameters)
 	namespaceoid = QualifiedNameGetCreationNamespace(names, &dictname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceoid);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceoid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -917,6 +918,7 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	namespaceoid = QualifiedNameGetCreationNamespace(names, &cfgname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceoid);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceoid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index cd38e9cddf4..d5e76fbb241 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -39,6 +39,7 @@
 #include "access/xact.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
+#include "catalog/dependency.h"
 #include "catalog/heap.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_am.h"
@@ -739,6 +740,7 @@ DefineDomain(ParseState *pstate, CreateDomainStmt *stmt)
 														&domainName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, domainNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, domainNamespace, GetUserId(),
 								ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
@@ -788,6 +790,7 @@ DefineDomain(ParseState *pstate, CreateDomainStmt *stmt)
 						TypeNameToString(stmt->typeName)),
 				 parser_errposition(pstate, stmt->typeName->location)));
 
+	LockNotPinnedObjectById(TypeRelationId, basetypeoid);
 	aclresult = object_aclcheck(TypeRelationId, basetypeoid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, basetypeoid);
@@ -1195,6 +1198,7 @@ DefineEnum(CreateEnumStmt *stmt)
 													  &enumName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, enumNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, enumNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -1420,6 +1424,7 @@ DefineRange(ParseState *pstate, CreateRangeStmt *stmt)
 													  &typeName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, typeNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, typeNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -2414,6 +2419,7 @@ findRangeCanonicalFunction(List *procname, Oid typeOid)
 						func_signature_string(procname, 1, NIL, argList))));
 
 	/* Also, range type's creator must have permission to call function */
+	LockNotPinnedObjectById(ProcedureRelationId, procOid);
 	aclresult = object_aclcheck(ProcedureRelationId, procOid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION, get_func_name(procOid));
@@ -2457,6 +2463,7 @@ findRangeSubtypeDiffFunction(List *procname, Oid subtype)
 						func_signature_string(procname, 2, NIL, argList))));
 
 	/* Also, range type's creator must have permission to call function */
+	LockNotPinnedObjectById(ProcedureRelationId, procOid);
 	aclresult = object_aclcheck(ProcedureRelationId, procOid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION, get_func_name(procOid));
@@ -3956,6 +3963,7 @@ AlterTypeOwner(List *names, Oid newOwnerId, ObjectType objecttype)
 			check_can_set_role(GetUserId(), newOwnerId);
 
 			/* New owner must have CREATE privilege on namespace */
+			LockNotPinnedObjectById(NamespaceRelationId, typTup->typnamespace);
 			aclresult = object_aclcheck(NamespaceRelationId, typTup->typnamespace,
 										newOwnerId,
 										ACL_CREATE);
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index fa508ea70c6..ac1d902e912 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -102,6 +102,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
 extern void LockNotPinnedObject(const ObjectAddress *object);
+extern void LockNotPinnedObjectById(Oid classid, Oid objid);
 extern bool isObjectPinned(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
-- 
2.34.1

  [text/x-diff] v20-0003-Add-Assert-guard-to-detect-permission-check-befo.patch (9.5K, ../../afCXPVNuvpf5ECGZ@bdtpg/4-v20-0003-Add-Assert-guard-to-detect-permission-check-befo.patch)
  download | inline diff:
From 1fe422038bf0494a8146be965045802e49be4fcf Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Mon, 27 Apr 2026 14:23:25 +0000
Subject: [PATCH v20 3/3] Add Assert guard to detect permission check before
 lock regressions

Add instrumentation under USE_ASSERT_CHECKING to detect cases where
object_aclcheck() is called on a referenced object before a lock is held on it,
which would widen the TOCTOU window between the permission check and the dependency
recording.

In recordMultipleDependencies() and changeDependencyFor(), for each referenced
object that had a permission check earlier in the same statement, assert that a
lock is already held. This catches any future code that adds a permission check
on a referenced object without first acquiring a lock.

The tracking records each (classId, objectId, mode) from object_aclcheck() and
pg_class_aclcheck(), filtering to only dependency-relevant ACL modes (ACL_CREATE,
ACL_USAGE on non namespaces, ACL_EXECUTE, ACL_TRIGGER, ACL_REFERENCES). Tracking
resets at each ProcessUtility() call. The tracking array is capped at 1024 entries
per statement, which is sufficient for any practical DDL command.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by:
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/aclchk.c         | 32 ++++++++++++
 src/backend/catalog/pg_depend.c      | 52 ++++++++++++++++++++
 src/backend/tcop/utility.c           |  3 ++
 src/include/catalog/aclcheck_track.h | 73 ++++++++++++++++++++++++++++
 src/tools/pgindent/typedefs.list     |  1 +
 5 files changed, 161 insertions(+)
  51.5% src/backend/catalog/
  46.7% src/include/catalog/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 67424fe3b0c..3c3b35910e1 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -76,6 +76,7 @@
 #include "parser/parse_type.h"
 #include "storage/lmgr.h"
 #include "utils/acl.h"
+#include "catalog/aclcheck_track.h"
 #include "utils/aclchk_internal.h"
 #include "utils/builtins.h"
 #include "utils/fmgroids.h"
@@ -3890,6 +3891,8 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, mode);
+
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4092,6 +4095,8 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, mode);
+
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5035,3 +5040,30 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Instrumentation to detect permission check before lock regressions.
+ * Only used in assert-enabled builds.
+ */
+#ifdef USE_ASSERT_CHECKING
+AclCheckEntry aclcheck_tracked[ACLCHECK_TRACK_MAX];
+int			aclcheck_tracked_count = 0;
+
+void
+aclcheck_track_reset(void)
+{
+	aclcheck_tracked_count = 0;
+}
+
+bool
+aclcheck_track_was_checked(Oid classId, Oid objectId)
+{
+	for (int i = 0; i < aclcheck_tracked_count; i++)
+	{
+		if (aclcheck_tracked[i].classId == classId &&
+			aclcheck_tracked[i].objectId == objectId)
+			return true;
+	}
+	return false;
+}
+#endif							/* USE_ASSERT_CHECKING */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 5618e3d26fa..28fa99b2d42 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -18,6 +18,7 @@
 #include "access/htup_details.h"
 #include "access/table.h"
 #include "catalog/catalog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/pg_constraint.h"
@@ -27,6 +28,8 @@
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -107,6 +110,31 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+#ifdef USE_ASSERT_CHECKING
+		/*
+		 * If this referenced object had a permission check earlier in this
+		 * statement, assert that a lock is already held on it.  This ensures
+		 * callers acquired the lock before calling object_aclcheck(), not
+		 * after. The latter would widen the TOCTOU window between the
+		 * permission check and the dependency recording.
+		 */
+		if (aclcheck_track_was_checked(referenced->classId, referenced->objectId))
+		{
+			if (referenced->classId == RelationRelationId)
+				Assert(CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			else
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag, MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId, 0);
+				Assert(LockHeldByMe(&tag, AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * Acquire a lock and check object still exists while recording the
 		 * dependency.
@@ -511,6 +539,30 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+#ifdef USE_ASSERT_CHECKING
+	/*
+	 * If this referenced object had a permission check earlier in this
+	 * statement, assert that a lock is already held on it.  This ensures
+	 * callers acquired the lock before calling object_aclcheck(), not after.
+	 * The latter would widen the TOCTOU window between the permission check and
+	 * the dependency recording.
+	 */
+	if (aclcheck_track_was_checked(objAddr.classId, objAddr.objectId))
+	{
+		if (objAddr.classId == RelationRelationId)
+			Assert(CheckRelationOidLockedByMe(objAddr.objectId,
+											  AccessShareLock, true));
+		else
+		{
+			LOCKTAG		tag;
+
+			SET_LOCKTAG_OBJECT(tag, MyDatabaseId,
+							   objAddr.classId,
+							   objAddr.objectId, 0);
+			Assert(LockHeldByMe(&tag, AccessShareLock, true));
+		}
+	}
+#endif
 	/*
 	 * Acquire a lock and check object still exists while changing the
 	 * dependency.
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..0c4d382bd37 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -21,6 +21,7 @@
 #include "access/xact.h"
 #include "access/xlog.h"
 #include "catalog/namespace.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
 #include "catalog/toasting.h"
@@ -515,6 +516,8 @@ ProcessUtility(PlannedStmt *pstmt,
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
+	aclcheck_track_reset();
+
 	/*
 	 * We provide a function hook variable that lets loadable plugins get
 	 * control when ProcessUtility is called.  Such a plugin would normally
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..5825d7398d3
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,73 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Instrumentation to detect permission check before lock via Assert in
+ *	  recordMultipleDependencies() and changeDependencyFor().
+ *
+ *	  Only active in USE_ASSERT_CHECKING builds.
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#ifdef USE_ASSERT_CHECKING
+
+#include "catalog/pg_namespace.h"
+
+#define ACLCHECK_TRACK_MAX 1024
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+} AclCheckEntry;
+
+extern AclCheckEntry aclcheck_tracked[];
+extern int	aclcheck_tracked_count;
+
+extern void aclcheck_track_reset(void);
+extern bool aclcheck_track_was_checked(Oid classId, Oid objectId);
+
+/*
+ * Only record aclchecks that are dependency-relevant:
+ * - ACL_CREATE on any object (creating something in a container)
+ * - ACL_USAGE on non-namespace objects (using a type, language, server)
+ * - ACL_EXECUTE on functions
+ * - ACL_TRIGGER, ACL_REFERENCES on relations
+ *
+ * Skip ACL_USAGE on namespaces — that's name resolution, not dependency.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, AclMode mode)
+{
+	/* Skip ACL_USAGE on namespaces (name resolution, not dependency) */
+	if (classId == NamespaceRelationId && !(mode & ACL_CREATE))
+		return;
+
+	/* Only track dependency-relevant modes */
+	if (!(mode & (ACL_CREATE | ACL_USAGE | ACL_EXECUTE | ACL_TRIGGER | ACL_REFERENCES)))
+		return;
+
+	if (aclcheck_tracked_count < ACLCHECK_TRACK_MAX)
+	{
+		aclcheck_tracked[aclcheck_tracked_count].classId = classId;
+		aclcheck_tracked[aclcheck_tracked_count].objectId = objectId;
+		aclcheck_tracked_count++;
+	}
+}
+
+#else							/* !USE_ASSERT_CHECKING */
+
+#define aclcheck_track_reset()			((void) 0)
+#define aclcheck_track_record(c, o, m)	((void) 0)
+#define aclcheck_track_was_checked(c, o) (false)
+
+#endif							/* USE_ASSERT_CHECKING */
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index 9f1dd55213d..0a8a2772b23 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -20,6 +20,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-05-13 20:20                                                               ` Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Robert Haas @ 2026-05-13 20:20 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Jeff Davis <pgsql@j-davis.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Tue, Apr 28, 2026 at 7:17 AM Bertrand Drouvot
<bertranddrouvot.pg@gmail.com> wrote:
> 0003: Add Assert guard to detect permission check before lock regressions
>
> Add instrumentation under USE_ASSERT_CHECKING to detect cases where object_aclcheck()
> is called on a referenced object before a lock is held on it, which would widen
> the TOCTOU window between the permission check and the dependency recording.

I really like the idea of having some kind of cross-check system that
can detect future (or current) coding mistakes. But what I wonder
about this mechanism is: should we instead be insisting that we take a
lock and check permissions on every dependency? Is it an error to
record a dependency on an object without any sort of permissions
check?

Also, I think the mechanism might not be entirely safe. ProcessUtility
can result in executing user-defined functions which could
theoretically run other DDL and then it seems like this code would get
confused.

-- 
Robert Haas
EDB: http://www.enterprisedb.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
@ 2026-05-18 12:14                                                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-05-18 12:14 UTC (permalink / raw)
  To: Robert Haas <robertmhaas@gmail.com>; +Cc: Jeff Davis <pgsql@j-davis.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, May 13, 2026 at 04:20:21PM -0400, Robert Haas wrote:
> On Tue, Apr 28, 2026 at 7:17 AM Bertrand Drouvot
> <bertranddrouvot.pg@gmail.com> wrote:
> > 0003: Add Assert guard to detect permission check before lock regressions
> >
> > Add instrumentation under USE_ASSERT_CHECKING to detect cases where object_aclcheck()
> > is called on a referenced object before a lock is held on it, which would widen
> > the TOCTOU window between the permission check and the dependency recording.
> 
> I really like the idea of having some kind of cross-check system that
> can detect future (or current) coding mistakes.

Thanks for the feedback! BTW, it detected a new one due to 4793fc41f82, so v21
attached does fix it to make the CI green.

> But what I wonder
> about this mechanism is: should we instead be insisting that we take a
> lock and check permissions on every dependency? Is it an error to
> record a dependency on an object without any sort of permissions
> check?

I'm not sure. For example, currently, without execute privilege on myfunc(), one
could create a view like:

CREATE VIEW v1 AS SELECT myfunc(a) FROM t1;

so that the dependency is recorded.

The execution permission is checked when the view is queried. I don't think this
example is a bug, so that I'm doubtful about insisting that we take a lock and
check permissions on every dependency.

> Also, I think the mechanism might not be entirely safe. ProcessUtility
> can result in executing user-defined functions which could
> theoretically run other DDL and then it seems like this code would get
> confused.

The assert fires when an aclcheck was tracked and the lock is not held. Since
the locks are transaction-scoped, any lock acquired during the statement persists,
so the assert passes regardless of nesting. So that looks not possible to get false
positives (assert fires) due to user-defined functions running other DDL.

The concern would be false negatives (missed detection) due to the reset wiping
the outer DDL's entries.

I believe, that's theoretically possible only if:

- The outer DDL has a P1 bug (aclcheck without lock on object X)
- A user-defined function happens to run DDL that also aclchecks and locks the same
object X
- The user-defined function DDL's lock satisfies the assert for the outer DDL

But then, the bug would be caught in normal testing without the user-defined
function being present.

So I'm not sure how this code could get confused. Do you have an example of what
you have in mind?

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v21-0001-Avoid-orphaned-objects-dependencies.patch (22.7K, ../../agsCqlLTytZCudMv@bdtpg/2-v21-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 3732333ec27f6a5c124520847adf545516f65360 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Mon, 27 Apr 2026 14:01:46 +0000
Subject: [PATCH v21 1/3] Avoid orphaned objects dependencies

Concurrent DDL can create orphaned dependencies in pg_depend, objects
referencing other objects that no longer exist. For example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

Fix by acquiring AccessShareLock on referenced objects when recording
dependencies. This conflicts with AccessExclusiveLock taken by DROP,
preventing the race. After acquiring the lock, verify the object still
exists, if it was dropped concurrently, report an error.

The lock and check is done in both recordMultipleDependencies() and
changeDependencyFor().

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by:
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/dependency.c              |  72 ++++++++++
 src/backend/catalog/objectaddress.c           |  65 +++++++++
 src/backend/catalog/pg_depend.c               |  16 ++-
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   2 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  96 +++++++++++++
 src/test/regress/expected/alter_table.out     |  11 +-
 10 files changed, 386 insertions(+), 8 deletions(-)
  26.4% src/backend/catalog/
  41.3% src/test/isolation/expected/
  27.7% src/test/isolation/specs/
   4.3% src/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index fdb8e67e1f5..7e26691393d 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -87,6 +87,7 @@
 #include "parser/parsetree.h"
 #include "rewrite/rewriteRemove.h"
 #include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/syscache.h"
@@ -1606,6 +1607,77 @@ ReleaseDeletionLock(const ObjectAddress *object)
 							 AccessExclusiveLock);
 }
 
+/*
+ * LockNotPinnedObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ *
+ * If the caller already holds a lock that conflicts with DROP
+ * (AccessShareLock or stronger), skip the lock acquisition entirely.
+ */
+void
+LockNotPinnedObject(const ObjectAddress *object)
+{
+	if (isObjectPinned(object))
+		return;
+
+	if (object->classId == RelationRelationId)
+	{
+		/* skip shared relations as they are pinned */
+		if (IsSharedRelation(object->objectId))
+			return;
+
+		/*
+		 * We must be in one of the two following cases that would already
+		 * prevent the relation to be dropped: 1. The relation is already
+		 * locked (could be an existing relation or a relation that we are
+		 * creating). 2. The relation is protected indirectly (i.e an index
+		 * protected by a lock on its table, a table protected by a lock on a
+		 * function that depends of the table...). To avoid any risks, acquire
+		 * a lock if there is none. That may add unnecessary lock for 2. but
+		 * that's worth it.
+		 */
+		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
+			LockRelationOid(object->objectId, AccessShareLock);
+		return;
+	}
+	else
+	{
+		LOCKTAG		tag;
+
+		SET_LOCKTAG_OBJECT(tag,
+						   MyDatabaseId,
+						   object->classId,
+						   object->objectId,
+						   0);
+
+		if (LockHeldByMe(&tag, AccessShareLock, true))
+			return;
+
+		/* assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+	}
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it (for example creating
+		 * a composite type while creating a relation), so bypass the syscache
+		 * lookup and use a SnapshotSelf scan instead to cover this scenario.
+		 */
+		if (!ObjectByIdExist(object, true))
+			ereport(ERROR,
+					(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+					 errmsg("dependent object does not exist"),
+					 errdetail("Class OID is %u and object OID is %u",
+							   object->classId, object->objectId)));
+	}
+}
+
 /*
  * recordDependencyOnExpr - find expression dependencies
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 050b7829eb0..b5786532af8 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -90,6 +90,7 @@
 #include "utils/lsyscache.h"
 #include "utils/memutils.h"
 #include "utils/regproc.h"
+#include "utils/snapmgr.h"
 #include "utils/syscache.h"
 
 /*
@@ -2696,6 +2697,70 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * If use_snapshot_self is false, uses the syscache (which sees committed data).
+ * If use_snapshot_self is true, does a direct catalog scan with SnapshotSelf
+ * to also see objects created in the current transaction.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_snapshot_self)
+{
+	HeapTuple	tuple;
+	SysCacheIdentifier cache = SYSCACHEID_INVALID;
+
+	if (!use_snapshot_self)
+	{
+		const ObjectPropertyType *property;
+
+		property = get_object_property_data(address->classId);
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache != SYSCACHEID_INVALID)
+	{
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+			return false;
+
+		ReleaseSysCache(tuple);
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		Snapshot	snapshot;
+
+		if (use_snapshot_self)
+			snapshot = SnapshotSelf;
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId),
+								  true, snapshot, 1, skey);
+
+		tuple = systable_getnext(scan);
+
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return HeapTupleIsValid(tuple);
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 07c2d41c189..5618e3d26fa 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -33,8 +33,6 @@
 #include "utils/syscache.h"
 
 
-static bool isObjectPinned(const ObjectAddress *object);
-
 
 /*
  * Record a dependency between 2 objects via their respective ObjectAddress.
@@ -109,6 +107,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency.
+		 */
+		LockNotPinnedObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
@@ -507,6 +511,12 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+	/*
+	 * Acquire a lock and check object still exists while changing the
+	 * dependency.
+	 */
+	LockNotPinnedObject(&objAddr);
+
 	depRel = table_open(DependRelationId, RowExclusiveLock);
 
 	/* There should be existing dependency record(s), so search. */
@@ -707,7 +717,7 @@ changeDependenciesOn(Oid refClassId, Oid oldRefObjectId,
  * The passed subId, if any, is ignored; we assume that only whole objects
  * are pinned (and that this implies pinning their components).
  */
-static bool
+bool
 isObjectPinned(const ObjectAddress *object)
 {
 	return IsPinnedObject(object->classId, object->objectId);
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 5b25402ebbe..58b498f68fc 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -278,6 +278,7 @@ Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 
 Section: Class 2D - Invalid Transaction Termination
 
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 2f3c1eae3c7..fa508ea70c6 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,8 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void LockNotPinnedObject(const ObjectAddress *object);
+extern bool isObjectPinned(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 1f965e1faef..960b7e4bfa6 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -54,6 +54,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_snapshot_self);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 00000000000..820680f5e16
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  dependent object does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  dependent object does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 1578ba191c8..83f626d51b5 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -126,3 +126,4 @@ test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
 test: for-portion-of
+test: test_dependencies_locks
\ No newline at end of file
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 00000000000..ee4130b2dc4
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,96 @@
+# Test that concurrent DDL properly prevents orphaned dependencies.
+#
+# When session 1 creates an object that depends on a referenced object,
+# and session 2 concurrently drops that referenced object, the lock
+# acquired during dependency recording must prevent the drop or the
+# create must fail with "dependent object does not exist".
+
+setup
+{
+	CREATE SCHEMA testschema;
+	CREATE SCHEMA alterschema;
+	CREATE TYPE public.foo as enum ('one', 'two');
+	CREATE TYPE public.footab as enum ('three', 'four');
+	CREATE DOMAIN id AS int;
+	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+	DROP FUNCTION IF EXISTS testschema.foo();
+	DROP FUNCTION IF EXISTS fooargtype(num foo);
+	DROP FUNCTION IF EXISTS footrettype();
+	DROP FUNCTION IF EXISTS foofunc();
+	DROP FUNCTION IF EXISTS public.falter();
+	DROP FUNCTION IF EXISTS alterschema.falter();
+	DROP DOMAIN IF EXISTS idid;
+	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP TABLE IF EXISTS tabtype;
+	DROP SCHEMA IF EXISTS testschema;
+	DROP SCHEMA IF EXISTS alterschema;
+	DROP TYPE IF EXISTS public.foo;
+	DROP TYPE IF EXISTS public.footab;
+	DROP DOMAIN IF EXISTS id;
+	DROP FUNCTION IF EXISTS f();
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 6dd22be0e8d..b891d68d4a7 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2949,11 +2949,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.34.1

  [text/x-diff] v21-0002-Lock-referenced-objects-before-permission-checks.patch (33.6K, ../../agsCqlLTytZCudMv@bdtpg/3-v21-0002-Lock-referenced-objects-before-permission-checks.patch)
  download | inline diff:
From b73a9b3523a03d7d0f31616ddb0450cb691e4ce7 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Mon, 27 Apr 2026 14:19:51 +0000
Subject: [PATCH v21 2/3] Lock referenced objects before permission checks in
 DDL commands

Add LockNotPinnedObjectById() calls before object_aclcheck() at all caller
sites where a permission check on a referenced object occurs before the
dependency on that object is recorded. This converts permission check before
lock to lock before permission check. It closes the TOCTOU window that could
allow a REVOKE to succeed between the permission check and the dependency
recording.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by:
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/dependency.c        | 22 ++++++++++++++++++++++
 src/backend/catalog/namespace.c         |  1 +
 src/backend/catalog/pg_aggregate.c      |  5 +++++
 src/backend/catalog/pg_cast.c           |  1 +
 src/backend/catalog/pg_operator.c       |  2 ++
 src/backend/commands/aggregatecmds.c    |  2 ++
 src/backend/commands/alter.c            |  3 +++
 src/backend/commands/collationcmds.c    |  2 ++
 src/backend/commands/conversioncmds.c   |  3 +++
 src/backend/commands/extension.c        |  1 +
 src/backend/commands/foreigncmds.c      |  5 +++++
 src/backend/commands/functioncmds.c     | 11 +++++++++++
 src/backend/commands/indexcmds.c        |  2 ++
 src/backend/commands/opclasscmds.c      |  2 ++
 src/backend/commands/operatorcmds.c     |  8 ++++++++
 src/backend/commands/statscmds.c        |  1 +
 src/backend/commands/subscriptioncmds.c |  4 ++++
 src/backend/commands/tablecmds.c        |  7 +++++++
 src/backend/commands/trigger.c          |  2 ++
 src/backend/commands/tsearchcmds.c      |  2 ++
 src/backend/commands/typecmds.c         |  9 +++++++++
 src/include/catalog/dependency.h        |  1 +
 22 files changed, 96 insertions(+)
  22.5% src/backend/catalog/
  76.2% src/backend/commands/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index 7e26691393d..a41e6ee2175 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1678,6 +1678,24 @@ LockNotPinnedObject(const ObjectAddress *object)
 	}
 }
 
+/*
+ * LockNotPinnedObjectById
+ *
+ * Lock the object if it is not pinned.  This is a convenience wrapper
+ * for callers that need to lock a referenced object before a permission
+ * check, converting permission check before lock to lock before permission
+ * check.
+ */
+void
+LockNotPinnedObjectById(Oid classid, Oid objid)
+{
+	ObjectAddress object;
+
+	ObjectAddressSet(object, classid, objid);
+
+	LockNotPinnedObject(&object);
+}
+
 /*
  * recordDependencyOnExpr - find expression dependencies
  *
@@ -1960,8 +1978,11 @@ find_expr_references_walker(Node *node,
 					objoid = DatumGetObjectId(con->constvalue);
 					if (SearchSysCacheExists1(PROCOID,
 											  ObjectIdGetDatum(objoid)))
+					{
+						LockNotPinnedObjectById(ProcedureRelationId, objoid);
 						add_object_address(ProcedureRelationId, objoid, 0,
 										   context->addrs);
+					}
 					break;
 				case REGOPEROID:
 				case REGOPERATOROID:
@@ -2057,6 +2078,7 @@ find_expr_references_walker(Node *node,
 	{
 		FuncExpr   *funcexpr = (FuncExpr *) node;
 
+		LockNotPinnedObjectById(ProcedureRelationId, funcexpr->funcid);
 		add_object_address(ProcedureRelationId, funcexpr->funcid, 0,
 						   context->addrs);
 		/* fall through to examine arguments */
diff --git a/src/backend/catalog/namespace.c b/src/backend/catalog/namespace.c
index 56b87d878e8..7dec076e111 100644
--- a/src/backend/catalog/namespace.c
+++ b/src/backend/catalog/namespace.c
@@ -3512,6 +3512,7 @@ LookupCreationNamespace(const char *nspname)
 
 	namespaceId = get_namespace_oid(nspname, false);
 
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/catalog/pg_aggregate.c b/src/backend/catalog/pg_aggregate.c
index 243b952b9cc..41b390e8d96 100644
--- a/src/backend/catalog/pg_aggregate.c
+++ b/src/backend/catalog/pg_aggregate.c
@@ -586,22 +586,26 @@ AggregateCreate(const char *aggName,
 	 */
 	for (i = 0; i < numArgs; i++)
 	{
+		LockNotPinnedObjectById(TypeRelationId, aggArgTypes[i]);
 		aclresult = object_aclcheck(TypeRelationId, aggArgTypes[i], GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, aggArgTypes[i]);
 	}
 
+	LockNotPinnedObjectById(TypeRelationId, aggTransType);
 	aclresult = object_aclcheck(TypeRelationId, aggTransType, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, aggTransType);
 
 	if (OidIsValid(aggmTransType))
 	{
+		LockNotPinnedObjectById(TypeRelationId, aggmTransType);
 		aclresult = object_aclcheck(TypeRelationId, aggmTransType, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, aggmTransType);
 	}
 
+	LockNotPinnedObjectById(TypeRelationId, finaltype);
 	aclresult = object_aclcheck(TypeRelationId, finaltype, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, finaltype);
@@ -909,6 +913,7 @@ lookup_agg_function(List *fnName,
 	}
 
 	/* Check aggregate creator has permission to call the function */
+	LockNotPinnedObjectById(ProcedureRelationId, fnOid);
 	aclresult = object_aclcheck(ProcedureRelationId, fnOid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION, get_func_name(fnOid));
diff --git a/src/backend/catalog/pg_cast.c b/src/backend/catalog/pg_cast.c
index 5119c2acda2..bb48e686f83 100644
--- a/src/backend/catalog/pg_cast.c
+++ b/src/backend/catalog/pg_cast.c
@@ -105,6 +105,7 @@ CastCreate(Oid sourcetypeid, Oid targettypeid,
 	/* dependency on function */
 	if (OidIsValid(funcid))
 	{
+		LockNotPinnedObjectById(ProcedureRelationId, funcid);
 		ObjectAddressSet(referenced, ProcedureRelationId, funcid);
 		add_exact_object_address(&referenced, addrs);
 	}
diff --git a/src/backend/catalog/pg_operator.c b/src/backend/catalog/pg_operator.c
index 6b90c774c18..a222358d081 100644
--- a/src/backend/catalog/pg_operator.c
+++ b/src/backend/catalog/pg_operator.c
@@ -654,6 +654,7 @@ get_other_operator(List *otherOp, Oid otherLeftTypeId, Oid otherRightTypeId,
 
 	/* not in catalogs, different from operator, so make shell */
 
+	LockNotPinnedObjectById(NamespaceRelationId, otherNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, otherNamespace, GetUserId(),
 								ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
@@ -876,6 +877,7 @@ makeOperatorDependencies(HeapTuple tuple,
 	/* Dependency on namespace */
 	if (OidIsValid(oper->oprnamespace))
 	{
+		LockNotPinnedObjectById(NamespaceRelationId, oper->oprnamespace);
 		ObjectAddressSet(referenced, NamespaceRelationId, oper->oprnamespace);
 		add_exact_object_address(&referenced, addrs);
 	}
diff --git a/src/backend/commands/aggregatecmds.c b/src/backend/commands/aggregatecmds.c
index 41b45dc6402..c2fb111daf3 100644
--- a/src/backend/commands/aggregatecmds.c
+++ b/src/backend/commands/aggregatecmds.c
@@ -22,6 +22,7 @@
  */
 #include "postgres.h"
 
+#include "catalog/dependency.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_aggregate.h"
 #include "catalog/pg_namespace.h"
@@ -101,6 +102,7 @@ DefineAggregate(ParseState *pstate,
 	aggNamespace = QualifiedNameGetCreationNamespace(name, &aggName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, aggNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, aggNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/commands/alter.c b/src/backend/commands/alter.c
index 74ceb5fe20d..03516cb0d2e 100644
--- a/src/backend/commands/alter.c
+++ b/src/backend/commands/alter.c
@@ -221,6 +221,7 @@ AlterObjectRename_internal(Relation rel, Oid objectId, const char *new_name)
 		/* User must have CREATE privilege on the namespace */
 		if (OidIsValid(namespaceId))
 		{
+			LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 			aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(),
 										ACL_CREATE);
 			if (aclresult != ACLCHECK_OK)
@@ -752,6 +753,7 @@ AlterObjectNamespace_internal(Relation rel, Oid objid, Oid nspOid)
 						   NameStr(*(DatumGetName(name))));
 
 		/* User must have CREATE privilege on new namespace */
+		LockNotPinnedObjectById(NamespaceRelationId, nspOid);
 		aclresult = object_aclcheck(NamespaceRelationId, nspOid, GetUserId(), ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -1014,6 +1016,7 @@ AlterObjectOwner_internal(Oid classId, Oid objectId, Oid new_ownerId)
 			{
 				AclResult	aclresult;
 
+				LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 				aclresult = object_aclcheck(NamespaceRelationId, namespaceId, new_ownerId,
 											ACL_CREATE);
 				if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/collationcmds.c b/src/backend/commands/collationcmds.c
index 0bc31ec2b6f..fa5dad1aa1f 100644
--- a/src/backend/commands/collationcmds.c
+++ b/src/backend/commands/collationcmds.c
@@ -21,6 +21,7 @@
 #include "access/htup_details.h"
 #include "access/table.h"
 #include "access/xact.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/namespace.h"
 #include "catalog/objectaccess.h"
@@ -82,6 +83,7 @@ DefineCollation(ParseState *pstate, List *names, List *parameters, bool if_not_e
 
 	collNamespace = QualifiedNameGetCreationNamespace(names, &collName);
 
+	LockNotPinnedObjectById(NamespaceRelationId, collNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, collNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/commands/conversioncmds.c b/src/backend/commands/conversioncmds.c
index 5f2022d3072..d60ecdb711a 100644
--- a/src/backend/commands/conversioncmds.c
+++ b/src/backend/commands/conversioncmds.c
@@ -14,6 +14,7 @@
  */
 #include "postgres.h"
 
+#include "catalog/dependency.h"
 #include "catalog/pg_conversion.h"
 #include "catalog/pg_namespace.h"
 #include "catalog/pg_proc.h"
@@ -50,6 +51,7 @@ CreateConversionCommand(CreateConversionStmt *stmt)
 													&conversion_name);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -97,6 +99,7 @@ CreateConversionCommand(CreateConversionStmt *stmt)
 						NameListToString(func_name), "integer")));
 
 	/* Check we have EXECUTE rights for the function */
+	LockNotPinnedObjectById(ProcedureRelationId, funcoid);
 	aclresult = object_aclcheck(ProcedureRelationId, funcoid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION,
diff --git a/src/backend/commands/extension.c b/src/backend/commands/extension.c
index a330b5fd6ce..4e82a010788 100644
--- a/src/backend/commands/extension.c
+++ b/src/backend/commands/extension.c
@@ -3283,6 +3283,7 @@ AlterExtensionNamespace(const char *extensionName, const char *newschema, Oid *o
 					   extensionName);
 
 	/* Permission check: must have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, nspOid);
 	aclresult = object_aclcheck(NamespaceRelationId, nspOid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA, newschema);
diff --git a/src/backend/commands/foreigncmds.c b/src/backend/commands/foreigncmds.c
index c4852be2eb2..dd31e260739 100644
--- a/src/backend/commands/foreigncmds.c
+++ b/src/backend/commands/foreigncmds.c
@@ -377,6 +377,7 @@ AlterForeignServerOwner_internal(Relation rel, HeapTuple tup, Oid newOwnerId)
 			check_can_set_role(GetUserId(), newOwnerId);
 
 			/* New owner must have USAGE privilege on foreign-data wrapper */
+			LockNotPinnedObjectById(ForeignDataWrapperRelationId, form->srvfdw);
 			aclresult = object_aclcheck(ForeignDataWrapperRelationId, form->srvfdw, newOwnerId, ACL_USAGE);
 			if (aclresult != ACLCHECK_OK)
 			{
@@ -997,6 +998,7 @@ CreateForeignServer(CreateForeignServerStmt *stmt)
 	 */
 	fdw = GetForeignDataWrapperByName(stmt->fdwname, false);
 
+	LockNotPinnedObjectById(ForeignDataWrapperRelationId, fdw->fdwid);
 	aclresult = object_aclcheck(ForeignDataWrapperRelationId, fdw->fdwid, ownerId, ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FDW, fdw->fdwname);
@@ -1188,6 +1190,7 @@ user_mapping_ddl_aclcheck(Oid umuserid, Oid serverid, const char *servername)
 		{
 			AclResult	aclresult;
 
+			LockNotPinnedObjectById(ForeignServerRelationId, serverid);
 			aclresult = object_aclcheck(ForeignServerRelationId, serverid, curuserid, ACL_USAGE);
 			if (aclresult != ACLCHECK_OK)
 				aclcheck_error(aclresult, OBJECT_FOREIGN_SERVER, servername);
@@ -1539,6 +1542,7 @@ CreateForeignTable(CreateForeignTableStmt *stmt, Oid relid)
 	 * get the actual FDW for option validation etc.
 	 */
 	server = GetForeignServerByName(stmt->servername, false);
+	LockNotPinnedObjectById(ForeignServerRelationId, server->serverid);
 	aclresult = object_aclcheck(ForeignServerRelationId, server->serverid, ownerId, ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FOREIGN_SERVER, server->servername);
@@ -1598,6 +1602,7 @@ ImportForeignSchema(ImportForeignSchemaStmt *stmt)
 
 	/* Check that the foreign server exists and that we have USAGE on it */
 	server = GetForeignServerByName(stmt->server_name, false);
+	LockNotPinnedObjectById(ForeignServerRelationId, server->serverid);
 	aclresult = object_aclcheck(ForeignServerRelationId, server->serverid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FOREIGN_SERVER, server->servername);
diff --git a/src/backend/commands/functioncmds.c b/src/backend/commands/functioncmds.c
index 3afd762e9dc..9aec534c390 100644
--- a/src/backend/commands/functioncmds.c
+++ b/src/backend/commands/functioncmds.c
@@ -146,6 +146,7 @@ compute_return_type(TypeName *returnType, Oid languageOid,
 				 errdetail("Creating a shell type definition.")));
 		namespaceId = QualifiedNameGetCreationNamespace(returnType->names,
 														&typname);
+		LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 		aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(),
 									ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
@@ -158,6 +159,7 @@ compute_return_type(TypeName *returnType, Oid languageOid,
 		CommandCounterIncrement();
 	}
 
+	LockNotPinnedObjectById(TypeRelationId, rettype);
 	aclresult = object_aclcheck(TypeRelationId, rettype, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, rettype);
@@ -274,6 +276,7 @@ interpret_function_parameter_list(ParseState *pstate,
 			toid = InvalidOid;	/* keep compiler quiet */
 		}
 
+		LockNotPinnedObjectById(TypeRelationId, toid);
 		aclresult = object_aclcheck(TypeRelationId, toid, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, toid);
@@ -1071,6 +1074,7 @@ CreateFunction(ParseState *pstate, CreateFunctionStmt *stmt)
 													&funcname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceId, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -1125,6 +1129,7 @@ CreateFunction(ParseState *pstate, CreateFunctionStmt *stmt)
 	if (languageStruct->lanpltrusted)
 	{
 		/* if trusted language, need USAGE privilege */
+		LockNotPinnedObjectById(LanguageRelationId, languageOid);
 		aclresult = object_aclcheck(LanguageRelationId, languageOid, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_LANGUAGE,
@@ -1582,10 +1587,12 @@ CreateCast(CreateCastStmt *stmt)
 						format_type_be(sourcetypeid),
 						format_type_be(targettypeid))));
 
+	LockNotPinnedObjectById(TypeRelationId, sourcetypeid);
 	aclresult = object_aclcheck(TypeRelationId, sourcetypeid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, sourcetypeid);
 
+	LockNotPinnedObjectById(TypeRelationId, targettypeid);
 	aclresult = object_aclcheck(TypeRelationId, targettypeid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, targettypeid);
@@ -1874,6 +1881,7 @@ CreateTransform(CreateTransformStmt *stmt)
 	if (!object_ownercheck(TypeRelationId, typeid, GetUserId()))
 		aclcheck_error_type(ACLCHECK_NOT_OWNER, typeid);
 
+	LockNotPinnedObjectById(TypeRelationId, typeid);
 	aclresult = object_aclcheck(TypeRelationId, typeid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, typeid);
@@ -1883,6 +1891,7 @@ CreateTransform(CreateTransformStmt *stmt)
 	 */
 	langid = get_language_oid(stmt->lang, false);
 
+	LockNotPinnedObjectById(LanguageRelationId, langid);
 	aclresult = object_aclcheck(LanguageRelationId, langid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_LANGUAGE, stmt->lang);
@@ -1897,6 +1906,7 @@ CreateTransform(CreateTransformStmt *stmt)
 		if (!object_ownercheck(ProcedureRelationId, fromsqlfuncid, GetUserId()))
 			aclcheck_error(ACLCHECK_NOT_OWNER, OBJECT_FUNCTION, NameListToString(stmt->fromsql->objname));
 
+		LockNotPinnedObjectById(ProcedureRelationId, fromsqlfuncid);
 		aclresult = object_aclcheck(ProcedureRelationId, fromsqlfuncid, GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_FUNCTION, NameListToString(stmt->fromsql->objname));
@@ -1923,6 +1933,7 @@ CreateTransform(CreateTransformStmt *stmt)
 		if (!object_ownercheck(ProcedureRelationId, tosqlfuncid, GetUserId()))
 			aclcheck_error(ACLCHECK_NOT_OWNER, OBJECT_FUNCTION, NameListToString(stmt->tosql->objname));
 
+		LockNotPinnedObjectById(ProcedureRelationId, tosqlfuncid);
 		aclresult = object_aclcheck(ProcedureRelationId, tosqlfuncid, GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_FUNCTION, NameListToString(stmt->tosql->objname));
diff --git a/src/backend/commands/indexcmds.c b/src/backend/commands/indexcmds.c
index 9ab74c8df0a..6216ab2a5f5 100644
--- a/src/backend/commands/indexcmds.c
+++ b/src/backend/commands/indexcmds.c
@@ -25,6 +25,7 @@
 #include "access/tableam.h"
 #include "access/xact.h"
 #include "catalog/catalog.h"
+#include "catalog/dependency.h"
 #include "catalog/index.h"
 #include "catalog/indexing.h"
 #include "catalog/namespace.h"
@@ -770,6 +771,7 @@ DefineIndex(ParseState *pstate,
 	{
 		AclResult	aclresult;
 
+		LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 		aclresult = object_aclcheck(NamespaceRelationId, namespaceId, root_save_userid,
 									ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/opclasscmds.c b/src/backend/commands/opclasscmds.c
index 7493a9ccc06..ad71ee53cb2 100644
--- a/src/backend/commands/opclasscmds.c
+++ b/src/backend/commands/opclasscmds.c
@@ -363,6 +363,7 @@ DefineOpClass(CreateOpClassStmt *stmt)
 													 &opcname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceoid);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceoid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -801,6 +802,7 @@ DefineOpFamily(CreateOpFamilyStmt *stmt)
 													 &opfname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceoid);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceoid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/commands/operatorcmds.c b/src/backend/commands/operatorcmds.c
index 3e7b09b3494..bb2ce833bdd 100644
--- a/src/backend/commands/operatorcmds.c
+++ b/src/backend/commands/operatorcmds.c
@@ -33,6 +33,7 @@
 
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_namespace.h"
@@ -92,6 +93,7 @@ DefineOperator(List *names, List *parameters)
 	oprNamespace = QualifiedNameGetCreationNamespace(names, &oprName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, oprNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, oprNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -189,6 +191,7 @@ DefineOperator(List *names, List *parameters)
 
 	if (typeName1)
 	{
+		LockNotPinnedObjectById(TypeRelationId, typeId1);
 		aclresult = object_aclcheck(TypeRelationId, typeId1, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, typeId1);
@@ -196,6 +199,7 @@ DefineOperator(List *names, List *parameters)
 
 	if (typeName2)
 	{
+		LockNotPinnedObjectById(TypeRelationId, typeId2);
 		aclresult = object_aclcheck(TypeRelationId, typeId2, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, typeId2);
@@ -227,12 +231,14 @@ DefineOperator(List *names, List *parameters)
 	 * necessary, since EXECUTE will be checked at any attempted use of the
 	 * operator, but it seems like a good idea anyway.
 	 */
+	LockNotPinnedObjectById(ProcedureRelationId, functionOid);
 	aclresult = object_aclcheck(ProcedureRelationId, functionOid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION,
 					   NameListToString(functionName));
 
 	rettype = get_func_rettype(functionOid);
+	LockNotPinnedObjectById(TypeRelationId, rettype);
 	aclresult = object_aclcheck(TypeRelationId, rettype, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, rettype);
@@ -312,6 +318,7 @@ ValidateRestrictionEstimator(List *restrictionName)
 	{
 		AclResult	aclresult;
 
+		LockNotPinnedObjectById(ProcedureRelationId, restrictionOid);
 		aclresult = object_aclcheck(ProcedureRelationId, restrictionOid,
 									GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
@@ -382,6 +389,7 @@ ValidateJoinEstimator(List *joinName)
 	{
 		AclResult	aclresult;
 
+		LockNotPinnedObjectById(ProcedureRelationId, joinOid);
 		aclresult = object_aclcheck(ProcedureRelationId, joinOid,
 									GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/statscmds.c b/src/backend/commands/statscmds.c
index b354723be44..6afef0f55c4 100644
--- a/src/backend/commands/statscmds.c
+++ b/src/backend/commands/statscmds.c
@@ -185,6 +185,7 @@ CreateStatistics(CreateStatsStmt *stmt, bool check_rights)
 	{
 		AclResult	aclresult;
 
+		LockNotPinnedObjectById(NamespaceRelationId, namespaceId);
 		aclresult = object_aclcheck(NamespaceRelationId, namespaceId,
 									GetUserId(), ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/subscriptioncmds.c b/src/backend/commands/subscriptioncmds.c
index 523959ba0ce..08dea4b67b3 100644
--- a/src/backend/commands/subscriptioncmds.c
+++ b/src/backend/commands/subscriptioncmds.c
@@ -745,6 +745,7 @@ CreateSubscription(ParseState *pstate, CreateSubscriptionStmt *stmt,
 		conninfo = NULL;
 
 		server = GetForeignServerByName(stmt->servername, false);
+		LockNotPinnedObjectById(ForeignServerRelationId, server->serverid);
 		aclresult = object_aclcheck(ForeignServerRelationId, server->serverid, owner, ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_FOREIGN_SERVER, server->servername);
@@ -1833,6 +1834,7 @@ AlterSubscription(ParseState *pstate, AlterSubscriptionStmt *stmt,
 				 * the server.
 				 */
 				new_server = GetForeignServerByName(stmt->servername, false);
+				LockNotPinnedObjectById(ForeignServerRelationId, new_server->serverid);
 				aclresult = object_aclcheck(ForeignServerRelationId,
 											new_server->serverid,
 											form->subowner, ACL_USAGE);
@@ -2262,6 +2264,7 @@ DropSubscription(DropSubscriptionStmt *stmt, bool isTopLevel)
 		ForeignServer *server;
 
 		server = GetForeignServer(form->subserver);
+		LockNotPinnedObjectById(ForeignServerRelationId, form->subserver);
 		aclresult = object_aclcheck(ForeignServerRelationId, form->subserver,
 									form->subowner, ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
@@ -2606,6 +2609,7 @@ AlterSubscriptionOwner_internal(Relation rel, HeapTuple tup, Oid newOwnerId)
 	{
 		ForeignServer *server = GetForeignServer(form->subserver);
 
+		LockNotPinnedObjectById(ForeignServerRelationId, server->serverid);
 		aclresult = object_aclcheck(ForeignServerRelationId, server->serverid, newOwnerId, ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			ereport(ERROR,
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 92b0f38c353..d95ef23a53f 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -30,6 +30,7 @@
 #include "access/xlog.h"
 #include "access/xloginsert.h"
 #include "catalog/catalog.h"
+#include "catalog/dependency.h"
 #include "catalog/heap.h"
 #include "catalog/index.h"
 #include "catalog/namespace.h"
@@ -997,6 +998,7 @@ DefineRelation(CreateStmt *stmt, char relkind, Oid ownerId,
 
 		ofTypeId = typenameTypeId(NULL, stmt->ofTypename);
 
+		LockNotPinnedObjectById(TypeRelationId, ofTypeId);
 		aclresult = object_aclcheck(TypeRelationId, ofTypeId, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, ofTypeId);
@@ -1462,6 +1464,7 @@ BuildDescForRelation(const List *columns)
 		attname = entry->colname;
 		typenameTypeIdAndMod(NULL, entry->typeName, &atttypid, &atttypmod);
 
+		LockNotPinnedObjectById(TypeRelationId, atttypid);
 		aclresult = object_aclcheck(TypeRelationId, atttypid, GetUserId(), ACL_USAGE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error_type(aclresult, atttypid);
@@ -13941,6 +13944,7 @@ checkFkeyPermissions(Relation rel, int16 *attnums, int natts)
 	int			i;
 
 	/* Okay if we have relation-level REFERENCES permission */
+	LockNotPinnedObjectById(RelationRelationId, RelationGetRelid(rel));
 	aclresult = pg_class_aclcheck(RelationGetRelid(rel), roleid,
 								  ACL_REFERENCES);
 	if (aclresult == ACLCHECK_OK)
@@ -14724,6 +14728,7 @@ ATPrepAlterColumnType(List **wqueue,
 	/* Look up the target type */
 	typenameTypeIdAndMod(pstate, typeName, &targettype, &targettypmod);
 
+	LockNotPinnedObjectById(TypeRelationId, targettype);
 	aclresult = object_aclcheck(TypeRelationId, targettype, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, targettype);
@@ -16476,6 +16481,7 @@ ATExecChangeOwner(Oid relationOid, Oid newOwnerId, bool recursing, LOCKMODE lock
 				check_can_set_role(GetUserId(), newOwnerId);
 
 				/* New owner must have CREATE privilege on namespace */
+				LockNotPinnedObjectById(NamespaceRelationId, namespaceOid);
 				aclresult = object_aclcheck(NamespaceRelationId, namespaceOid, newOwnerId,
 											ACL_CREATE);
 				if (aclresult != ACLCHECK_OK)
@@ -19882,6 +19888,7 @@ RangeVarCallbackForAlterRelation(const RangeVar *rv, Oid relid, Oid oldrelid,
 	 */
 	if (IsA(stmt, RenameStmt))
 	{
+		LockNotPinnedObjectById(NamespaceRelationId, classform->relnamespace);
 		aclresult = object_aclcheck(NamespaceRelationId, classform->relnamespace,
 									GetUserId(), ACL_CREATE);
 		if (aclresult != ACLCHECK_OK)
diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c
index b87b4b40d07..3c5ca8fe7e3 100644
--- a/src/backend/commands/trigger.c
+++ b/src/backend/commands/trigger.c
@@ -350,6 +350,7 @@ CreateTriggerFiringOn(const CreateTrigStmt *stmt, const char *queryString,
 
 		if (OidIsValid(constrrelid))
 		{
+			LockNotPinnedObjectById(RelationRelationId, constrrelid);
 			aclresult = pg_class_aclcheck(constrrelid, GetUserId(),
 										  ACL_TRIGGER);
 			if (aclresult != ACLCHECK_OK)
@@ -695,6 +696,7 @@ CreateTriggerFiringOn(const CreateTrigStmt *stmt, const char *queryString,
 		funcoid = LookupFuncName(stmt->funcname, 0, NULL, false);
 	if (!isInternal)
 	{
+		LockNotPinnedObjectById(ProcedureRelationId, funcoid);
 		aclresult = object_aclcheck(ProcedureRelationId, funcoid, GetUserId(), ACL_EXECUTE);
 		if (aclresult != ACLCHECK_OK)
 			aclcheck_error(aclresult, OBJECT_FUNCTION,
diff --git a/src/backend/commands/tsearchcmds.c b/src/backend/commands/tsearchcmds.c
index a12ce33bae4..eb9e68bbb91 100644
--- a/src/backend/commands/tsearchcmds.c
+++ b/src/backend/commands/tsearchcmds.c
@@ -414,6 +414,7 @@ DefineTSDictionary(List *names, List *parameters)
 	namespaceoid = QualifiedNameGetCreationNamespace(names, &dictname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceoid);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceoid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -917,6 +918,7 @@ DefineTSConfiguration(List *names, List *parameters, ObjectAddress *copied)
 	namespaceoid = QualifiedNameGetCreationNamespace(names, &cfgname);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, namespaceoid);
 	aclresult = object_aclcheck(NamespaceRelationId, namespaceoid, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
diff --git a/src/backend/commands/typecmds.c b/src/backend/commands/typecmds.c
index c4c3cdb5461..0e01dda90ba 100644
--- a/src/backend/commands/typecmds.c
+++ b/src/backend/commands/typecmds.c
@@ -39,6 +39,7 @@
 #include "access/xact.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
+#include "catalog/dependency.h"
 #include "catalog/heap.h"
 #include "catalog/objectaccess.h"
 #include "catalog/pg_am.h"
@@ -739,6 +740,7 @@ DefineDomain(ParseState *pstate, CreateDomainStmt *stmt)
 														&domainName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, domainNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, domainNamespace, GetUserId(),
 								ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
@@ -788,6 +790,7 @@ DefineDomain(ParseState *pstate, CreateDomainStmt *stmt)
 						TypeNameToString(stmt->typeName)),
 				 parser_errposition(pstate, stmt->typeName->location)));
 
+	LockNotPinnedObjectById(TypeRelationId, basetypeoid);
 	aclresult = object_aclcheck(TypeRelationId, basetypeoid, GetUserId(), ACL_USAGE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error_type(aclresult, basetypeoid);
@@ -1195,6 +1198,7 @@ DefineEnum(CreateEnumStmt *stmt)
 													  &enumName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, enumNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, enumNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -1420,6 +1424,7 @@ DefineRange(ParseState *pstate, CreateRangeStmt *stmt)
 													  &typeName);
 
 	/* Check we have creation rights in target namespace */
+	LockNotPinnedObjectById(NamespaceRelationId, typeNamespace);
 	aclresult = object_aclcheck(NamespaceRelationId, typeNamespace, GetUserId(), ACL_CREATE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_SCHEMA,
@@ -1496,6 +1501,7 @@ DefineRange(ParseState *pstate, CreateRangeStmt *stmt)
 																	&multirangeTypeName);
 
 			/* Check we have creation rights in target namespace */
+			LockNotPinnedObjectById(NamespaceRelationId, multirangeNamespace);
 			aclresult = object_aclcheck(NamespaceRelationId, multirangeNamespace,
 										GetUserId(), ACL_CREATE);
 			if (aclresult != ACLCHECK_OK)
@@ -2421,6 +2427,7 @@ findRangeCanonicalFunction(List *procname, Oid typeOid)
 						func_signature_string(procname, 1, NIL, argList))));
 
 	/* Also, range type's creator must have permission to call function */
+	LockNotPinnedObjectById(ProcedureRelationId, procOid);
 	aclresult = object_aclcheck(ProcedureRelationId, procOid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION, get_func_name(procOid));
@@ -2464,6 +2471,7 @@ findRangeSubtypeDiffFunction(List *procname, Oid subtype)
 						func_signature_string(procname, 2, NIL, argList))));
 
 	/* Also, range type's creator must have permission to call function */
+	LockNotPinnedObjectById(ProcedureRelationId, procOid);
 	aclresult = object_aclcheck(ProcedureRelationId, procOid, GetUserId(), ACL_EXECUTE);
 	if (aclresult != ACLCHECK_OK)
 		aclcheck_error(aclresult, OBJECT_FUNCTION, get_func_name(procOid));
@@ -3963,6 +3971,7 @@ AlterTypeOwner(List *names, Oid newOwnerId, ObjectType objecttype)
 			check_can_set_role(GetUserId(), newOwnerId);
 
 			/* New owner must have CREATE privilege on namespace */
+			LockNotPinnedObjectById(NamespaceRelationId, typTup->typnamespace);
 			aclresult = object_aclcheck(NamespaceRelationId, typTup->typnamespace,
 										newOwnerId,
 										ACL_CREATE);
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index fa508ea70c6..ac1d902e912 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -102,6 +102,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
 extern void LockNotPinnedObject(const ObjectAddress *object);
+extern void LockNotPinnedObjectById(Oid classid, Oid objid);
 extern bool isObjectPinned(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
-- 
2.34.1

  [text/x-diff] v21-0003-Add-Assert-guard-to-detect-permission-check-befo.patch (9.5K, ../../agsCqlLTytZCudMv@bdtpg/4-v21-0003-Add-Assert-guard-to-detect-permission-check-befo.patch)
  download | inline diff:
From 75143d7f2019248d1e403ae0a5045c89e85a06ec Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Mon, 27 Apr 2026 14:23:25 +0000
Subject: [PATCH v21 3/3] Add Assert guard to detect permission check before
 lock regressions

Add instrumentation under USE_ASSERT_CHECKING to detect cases where
object_aclcheck() is called on a referenced object before a lock is held on it,
which would widen the TOCTOU window between the permission check and the dependency
recording.

In recordMultipleDependencies() and changeDependencyFor(), for each referenced
object that had a permission check earlier in the same statement, assert that a
lock is already held. This catches any future code that adds a permission check
on a referenced object without first acquiring a lock.

The tracking records each (classId, objectId, mode) from object_aclcheck() and
pg_class_aclcheck(), filtering to only dependency-relevant ACL modes (ACL_CREATE,
ACL_USAGE on non namespaces, ACL_EXECUTE, ACL_TRIGGER, ACL_REFERENCES). Tracking
resets at each ProcessUtility() call. The tracking array is capped at 1024 entries
per statement, which is sufficient for any practical DDL command.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by:
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/aclchk.c         | 32 ++++++++++++
 src/backend/catalog/pg_depend.c      | 52 ++++++++++++++++++++
 src/backend/tcop/utility.c           |  3 ++
 src/include/catalog/aclcheck_track.h | 73 ++++++++++++++++++++++++++++
 src/tools/pgindent/typedefs.list     |  1 +
 5 files changed, 161 insertions(+)
  51.5% src/backend/catalog/
  46.7% src/include/catalog/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 007ede997c5..d13667f38a8 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -76,6 +76,7 @@
 #include "parser/parse_type.h"
 #include "storage/lmgr.h"
 #include "utils/acl.h"
+#include "catalog/aclcheck_track.h"
 #include "utils/aclchk_internal.h"
 #include "utils/builtins.h"
 #include "utils/fmgroids.h"
@@ -3891,6 +3892,8 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, mode);
+
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4093,6 +4096,8 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, mode);
+
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5036,3 +5041,30 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Instrumentation to detect permission check before lock regressions.
+ * Only used in assert-enabled builds.
+ */
+#ifdef USE_ASSERT_CHECKING
+AclCheckEntry aclcheck_tracked[ACLCHECK_TRACK_MAX];
+int			aclcheck_tracked_count = 0;
+
+void
+aclcheck_track_reset(void)
+{
+	aclcheck_tracked_count = 0;
+}
+
+bool
+aclcheck_track_was_checked(Oid classId, Oid objectId)
+{
+	for (int i = 0; i < aclcheck_tracked_count; i++)
+	{
+		if (aclcheck_tracked[i].classId == classId &&
+			aclcheck_tracked[i].objectId == objectId)
+			return true;
+	}
+	return false;
+}
+#endif							/* USE_ASSERT_CHECKING */
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 5618e3d26fa..28fa99b2d42 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -18,6 +18,7 @@
 #include "access/htup_details.h"
 #include "access/table.h"
 #include "catalog/catalog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
 #include "catalog/pg_constraint.h"
@@ -27,6 +28,8 @@
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -107,6 +110,31 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+#ifdef USE_ASSERT_CHECKING
+		/*
+		 * If this referenced object had a permission check earlier in this
+		 * statement, assert that a lock is already held on it.  This ensures
+		 * callers acquired the lock before calling object_aclcheck(), not
+		 * after. The latter would widen the TOCTOU window between the
+		 * permission check and the dependency recording.
+		 */
+		if (aclcheck_track_was_checked(referenced->classId, referenced->objectId))
+		{
+			if (referenced->classId == RelationRelationId)
+				Assert(CheckRelationOidLockedByMe(referenced->objectId,
+												  AccessShareLock, true));
+			else
+			{
+				LOCKTAG		tag;
+
+				SET_LOCKTAG_OBJECT(tag, MyDatabaseId,
+								   referenced->classId,
+								   referenced->objectId, 0);
+				Assert(LockHeldByMe(&tag, AccessShareLock, true));
+			}
+		}
+#endif
+
 		/*
 		 * Acquire a lock and check object still exists while recording the
 		 * dependency.
@@ -511,6 +539,30 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+#ifdef USE_ASSERT_CHECKING
+	/*
+	 * If this referenced object had a permission check earlier in this
+	 * statement, assert that a lock is already held on it.  This ensures
+	 * callers acquired the lock before calling object_aclcheck(), not after.
+	 * The latter would widen the TOCTOU window between the permission check and
+	 * the dependency recording.
+	 */
+	if (aclcheck_track_was_checked(objAddr.classId, objAddr.objectId))
+	{
+		if (objAddr.classId == RelationRelationId)
+			Assert(CheckRelationOidLockedByMe(objAddr.objectId,
+											  AccessShareLock, true));
+		else
+		{
+			LOCKTAG		tag;
+
+			SET_LOCKTAG_OBJECT(tag, MyDatabaseId,
+							   objAddr.classId,
+							   objAddr.objectId, 0);
+			Assert(LockHeldByMe(&tag, AccessShareLock, true));
+		}
+	}
+#endif
 	/*
 	 * Acquire a lock and check object still exists while changing the
 	 * dependency.
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..0c4d382bd37 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -21,6 +21,7 @@
 #include "access/xact.h"
 #include "access/xlog.h"
 #include "catalog/namespace.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
 #include "catalog/toasting.h"
@@ -515,6 +516,8 @@ ProcessUtility(PlannedStmt *pstmt,
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
+	aclcheck_track_reset();
+
 	/*
 	 * We provide a function hook variable that lets loadable plugins get
 	 * control when ProcessUtility is called.  Such a plugin would normally
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..5825d7398d3
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,73 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Instrumentation to detect permission check before lock via Assert in
+ *	  recordMultipleDependencies() and changeDependencyFor().
+ *
+ *	  Only active in USE_ASSERT_CHECKING builds.
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#ifdef USE_ASSERT_CHECKING
+
+#include "catalog/pg_namespace.h"
+
+#define ACLCHECK_TRACK_MAX 1024
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+} AclCheckEntry;
+
+extern AclCheckEntry aclcheck_tracked[];
+extern int	aclcheck_tracked_count;
+
+extern void aclcheck_track_reset(void);
+extern bool aclcheck_track_was_checked(Oid classId, Oid objectId);
+
+/*
+ * Only record aclchecks that are dependency-relevant:
+ * - ACL_CREATE on any object (creating something in a container)
+ * - ACL_USAGE on non-namespace objects (using a type, language, server)
+ * - ACL_EXECUTE on functions
+ * - ACL_TRIGGER, ACL_REFERENCES on relations
+ *
+ * Skip ACL_USAGE on namespaces — that's name resolution, not dependency.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, AclMode mode)
+{
+	/* Skip ACL_USAGE on namespaces (name resolution, not dependency) */
+	if (classId == NamespaceRelationId && !(mode & ACL_CREATE))
+		return;
+
+	/* Only track dependency-relevant modes */
+	if (!(mode & (ACL_CREATE | ACL_USAGE | ACL_EXECUTE | ACL_TRIGGER | ACL_REFERENCES)))
+		return;
+
+	if (aclcheck_tracked_count < ACLCHECK_TRACK_MAX)
+	{
+		aclcheck_tracked[aclcheck_tracked_count].classId = classId;
+		aclcheck_tracked[aclcheck_tracked_count].objectId = objectId;
+		aclcheck_tracked_count++;
+	}
+}
+
+#else							/* !USE_ASSERT_CHECKING */
+
+#define aclcheck_track_reset()			((void) 0)
+#define aclcheck_track_record(c, o, m)	((void) 0)
+#define aclcheck_track_was_checked(c, o) (false)
+
+#endif							/* USE_ASSERT_CHECKING */
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index 8cf40c87043..cb0cc25bda8 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -19,6 +19,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-05-26 18:00                                                                   ` Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Heikki Linnakangas @ 2026-05-26 18:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Robert Haas <robertmhaas@gmail.com>; +Cc: Jeff Davis <pgsql@j-davis.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On 18/05/2026 15:14, Bertrand Drouvot wrote:
> On Wed, May 13, 2026 at 04:20:21PM -0400, Robert Haas wrote:
>> On Tue, Apr 28, 2026 at 7:17 AM Bertrand Drouvot
>> <bertranddrouvot.pg@gmail.com> wrote:
>>> 0003: Add Assert guard to detect permission check before lock regressions
>>>
>>> Add instrumentation under USE_ASSERT_CHECKING to detect cases where object_aclcheck()
>>> is called on a referenced object before a lock is held on it, which would widen
>>> the TOCTOU window between the permission check and the dependency recording.
>>
>> I really like the idea of having some kind of cross-check system that
>> can detect future (or current) coding mistakes.
> 
> Thanks for the feedback! BTW, it detected a new one due to 4793fc41f82, so v21
> attached does fix it to make the CI green.

I had a closer look at patch 0001. It doesn't fix all the problems, we 
definitely need patch 0002/0003 too, but it's a good step forward and I 
think it makes sense to commit it independently. So I'm focusing on that 
now.

I noticed we are already doing essentially the same thing for shared 
dependencies, in shdepLockAndCheckObject(). I see that you even copied 
the function comment from shdepLockAndCheckObject() to 
LockNotPinnedObject(), but I didn't see it being otherwise mentioned in 
this thread. In any case, that's a good argument for doing the same for 
non-shared dependencies that we already do for shared dependencies.

> +	if (object->classId == RelationRelationId)
> +	{
> +		/* skip shared relations as they are pinned */
> +		if (IsSharedRelation(object->objectId))
> +			return;
> +
> +		/*
> +		 * We must be in one of the two following cases that would already
> +		 * prevent the relation to be dropped: 1. The relation is already
> +		 * locked (could be an existing relation or a relation that we are
> +		 * creating). 2. The relation is protected indirectly (i.e an index
> +		 * protected by a lock on its table, a table protected by a lock on a
> +		 * function that depends of the table...). To avoid any risks, acquire
> +		 * a lock if there is none. That may add unnecessary lock for 2. but
> +		 * that's worth it.
> +		 */
> +		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
> +			LockRelationOid(object->objectId, AccessShareLock);
> +		return;
> +	}

Hmm, shouldn't that re-check that the relation exists, after acquiring 
the lock, like the non-relation codepath does? Otherwise it's a little 
pointless to acquire the lock.

I did a bunch of little refactorings and ended up with the attached. 
Notable changes:

- I renamed and moved LockNotPinnedObject() into 
dependencyLockAndCheckObject(), for consistency with 
shdepLockAndCheckObject().

- Removed ObjectByIdExist(), inlined it into the caller. The argument to 
use SnapshotSelf or not seemed a bit too special to be generally useful

- Changed the error message and code to rhyme with the existing "role 
<OID> was concurrently dropped" errors. I didn't add the OID to the 
error message however, because that makes the testing hard. It'd be nice 
to have a general masking mechanism for OIDs and XIDs in error messages 
in tests, but now is not the time for that.

- Added a test for a dependency on a role too, to cover the existing 
shdepLockAndCheckObject() function. It's currently disabled because it 
prints the OID, though.


- Heikki

Attachments:

  [text/x-patch] v22-0001-Avoid-orphaned-objects-dependencies.patch (20.9K, ../../aebf583b-b904-4035-a1c1-a4c5ad064dec@iki.fi/2-v22-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From d51523d9003c902f3968e174f158c27680eab427 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Mon, 27 Apr 2026 14:01:46 +0000
Subject: [PATCH v22 1/1] Avoid orphaned objects dependencies

Concurrent DDL can create orphaned dependencies in pg_depend, objects
referencing other objects that no longer exist. For example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

Fix by acquiring AccessShareLock on referenced objects when recording
dependencies. This conflicts with AccessExclusiveLock taken by DROP,
preventing the race. After acquiring the lock, verify the object still
exists, if it was dropped concurrently, report an error.

The lock and check is done in both recordMultipleDependencies() and
changeDependencyFor().

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Heikki Linnakangas <heikki.linnakangas@iki.fi>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/pg_depend.c               | 130 +++++++++++++++++
 .../expected/test_dependencies_locks.out      | 137 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        | 108 ++++++++++++++
 src/test/regress/expected/alter_table.out     |  11 +-
 5 files changed, 382 insertions(+), 5 deletions(-)
 create mode 100644 src/test/isolation/expected/test_dependencies_locks.out
 create mode 100644 src/test/isolation/specs/test_dependencies_locks.spec

diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 07c2d41c189..ff17d5850c5 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -19,6 +19,7 @@
 #include "access/table.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
+#include "catalog/index.h"
 #include "catalog/indexing.h"
 #include "catalog/pg_constraint.h"
 #include "catalog/pg_depend.h"
@@ -27,13 +28,17 @@
 #include "catalog/partition.h"
 #include "commands/extension.h"
 #include "miscadmin.h"
+#include "storage/lmgr.h"
+#include "storage/lock.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
+#include "utils/snapmgr.h"
 #include "utils/syscache.h"
 
 
 static bool isObjectPinned(const ObjectAddress *object);
+static void dependencyLockAndCheckObject(Oid classId, Oid objectId);
 
 
 /*
@@ -109,6 +114,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency.
+		 */
+		dependencyLockAndCheckObject(referenced->classId, referenced->objectId);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
@@ -507,6 +518,13 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+	/*
+	 * Make sure the new referenced object doesn't go away while we record the
+	 * dependency.
+	 */
+	if (!newIsPinned)
+		dependencyLockAndCheckObject(refClassId, newRefObjectId);
+
 	depRel = table_open(DependRelationId, RowExclusiveLock);
 
 	/* There should be existing dependency record(s), so search. */
@@ -714,6 +732,118 @@ isObjectPinned(const ObjectAddress *object)
 }
 
 
+/*
+ * dependencyLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.  After it's
+ * locked, verify that it hasn't been dropped while we weren't looking.  If
+ * the object has been dropped, an error is thrown.
+ *
+ * If the caller already holds a lock that conflicts with DROP
+ * (AccessShareLock or stronger), this does nothing.  That is the desired case
+ * - callers should acquire the lock when they look up the object already -
+ * but many callers are skipping it currently.  This is a backstop to make
+ * that we don't record a bogus reference permanently in the catalogs.  In the
+ * future, after we have tightened up all the callers, this could just verify
+ * that all the objects are indeed locked and throw an error if not.
+ */
+static void
+dependencyLockAndCheckObject(Oid classId, Oid objectId)
+{
+	/*
+	 * Pinned objects cannot be dropped concurrently, and callers checked this
+	 * already.
+	 */
+	Assert(!IsPinnedObject(classId, objectId));
+
+	if (classId != RelationRelationId)
+	{
+		LOCKTAG		tag;
+		SysCacheIdentifier cache;
+		Relation rel;
+		SysScanDesc scan;
+		ScanKeyData skey;
+		HeapTuple tuple;
+
+		SET_LOCKTAG_OBJECT(tag,
+						   MyDatabaseId,
+						   classId,
+						   objectId,
+						   0);
+
+		if (LockHeldByMe(&tag, AccessShareLock, true))
+			return;
+
+		/* Assume we should lock the whole object not a sub-object */
+		LockDatabaseObject(classId, objectId, 0, AccessShareLock);
+
+		/*
+		 * Check that the object still exists.  If the catalog has a suitable
+		 * syscache, check that first.
+		 */
+		cache = get_object_catcache_oid(classId);
+		if (cache != SYSCACHEID_INVALID)
+		{
+			if (SearchSysCacheExists1(cache, ObjectIdGetDatum(objectId)))
+				return;
+		}
+
+		/*
+		 * If it's not found in the syscache, or there's no suitable syscache
+		 * we can use, scan the catalog table using SnapshotSelf.  This
+		 * handles the case that it's an object we just created (for example,
+		 * if it's a composite type created as part of creating a table).
+		 */
+		rel = table_open(classId, AccessShareLock);
+
+		ScanKeyInit(&skey,
+					get_object_attnum_oid(classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(classId),
+								  true, SnapshotSelf, 1, &skey);
+
+		tuple = systable_getnext(scan);
+		if (!HeapTupleIsValid(tuple))
+			ereport(ERROR,
+					(errcode(ERRCODE_UNDEFINED_OBJECT),
+					 errmsg("dependent %s was concurrently dropped",
+							get_object_class_descr(classId))));
+
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+	}
+	else
+	{
+		/*
+		 * Same logic for pg_class entries, but locking relations is handled
+		 * by different functions.
+		 *
+		 * Callers are more careful with locking relations than other objects,
+		 * so we should already have a lock on the relation, or on another
+		 * object that indirectly prevents the relation from being dropped.
+		 * For example, we might have a strong lock on a table while adding
+		 * dependency to its index.  However, we cannot detect the indirectly
+		 * protected case here easily.  To err on the safe side, acquire a
+		 * lock directly on the relation if we're not holding one already.
+		 */
+
+		/* all shared relations are pinned */
+		Assert(!IsSharedRelation(objectId));
+
+		if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
+			return;
+		LockRelationOid(objectId, AccessShareLock);
+
+		if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
+			return;
+		ereport(ERROR,
+				(errcode(ERRCODE_UNDEFINED_OBJECT),
+				 errmsg("dependent relation was concurrently dropped")));
+	}
+}
+
 /*
  * Various special-purpose lookups and manipulations of pg_depend.
  */
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 00000000000..3bf9e435725
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,137 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  dependent schema was concurrently dropped
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  dependent schema was concurrently dropped
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  dependent type was concurrently dropped
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  dependent type was concurrently dropped
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  dependent function was concurrently dropped
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  dependent type was concurrently dropped
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  dependent type was concurrently dropped
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  dependent foreign-data wrapper was concurrently dropped
+
+starting permutation: s1_begin s1_alter_function_owner s2_drop_role s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_owner: ALTER FUNCTION public.falter() OWNER TO regress_dependency;
+step s2_drop_role: DROP ROLE regress_dependency; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_role: <... completed>
+ERROR:  role "regress_dependency" cannot be dropped because some objects depend on it
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 1578ba191c8..83f626d51b5 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -126,3 +126,4 @@ test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
 test: for-portion-of
+test: test_dependencies_locks
\ No newline at end of file
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 00000000000..fd80c9cb9b7
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,108 @@
+# Test that concurrent DDL properly prevents orphaned dependencies.
+#
+# When session 1 creates an object that depends on a referenced object,
+# and session 2 concurrently drops that referenced object, the lock
+# acquired during dependency recording must prevent the drop or the
+# create must fail with "dependent object does not exist".
+
+setup
+{
+	CREATE SCHEMA testschema;
+	CREATE SCHEMA alterschema;
+	CREATE TYPE public.foo as enum ('one', 'two');
+	CREATE TYPE public.footab as enum ('three', 'four');
+	CREATE DOMAIN id AS int;
+	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+	CREATE ROLE regress_dependency;
+}
+
+teardown
+{
+	DROP FUNCTION IF EXISTS testschema.foo();
+	DROP FUNCTION IF EXISTS fooargtype(num foo);
+	DROP FUNCTION IF EXISTS footrettype();
+	DROP FUNCTION IF EXISTS foofunc();
+	DROP FUNCTION IF EXISTS public.falter();
+	DROP FUNCTION IF EXISTS alterschema.falter();
+	DROP DOMAIN IF EXISTS idid;
+	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP TABLE IF EXISTS tabtype;
+	DROP SCHEMA IF EXISTS testschema;
+	DROP SCHEMA IF EXISTS alterschema;
+	DROP TYPE IF EXISTS public.foo;
+	DROP TYPE IF EXISTS public.footab;
+	DROP DOMAIN IF EXISTS id;
+	DROP FUNCTION IF EXISTS f();
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+	DROP ROLE regress_dependency;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_owner" { ALTER FUNCTION public.falter() OWNER TO regress_dependency; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_drop_role" { DROP ROLE regress_dependency; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
+
+# function - role
+permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
+
+# XXX: This permutation is disabled because the error message, "role
+# <OID> was concurrently dropped", contains an OID that is not stable.
+#
+# permutation "s2_begin" "s2_drop_role" "s1_alter_function_owner" "s2_commit"
diff --git a/src/test/regress/expected/alter_table.out b/src/test/regress/expected/alter_table.out
index 6dd22be0e8d..b891d68d4a7 100644
--- a/src/test/regress/expected/alter_table.out
+++ b/src/test/regress/expected/alter_table.out
@@ -2949,11 +2949,12 @@ begin;
 alter table alterlock2
 add constraint alterlock2nv foreign key (f1) references alterlock (f1) NOT VALID;
 select * from my_locks order by 1;
-  relname   |     max_lockmode      
-------------+-----------------------
- alterlock  | ShareRowExclusiveLock
- alterlock2 | ShareRowExclusiveLock
-(2 rows)
+    relname     |     max_lockmode      
+----------------+-----------------------
+ alterlock      | ShareRowExclusiveLock
+ alterlock2     | ShareRowExclusiveLock
+ alterlock_pkey | AccessShareLock
+(3 rows)
 
 commit;
 begin;
-- 
2.47.3



^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
@ 2026-05-26 20:18                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-05-26 20:18 UTC (permalink / raw)
  To: Heikki Linnakangas <hlinnaka@iki.fi>; +Cc: Robert Haas <robertmhaas@gmail.com>; Jeff Davis <pgsql@j-davis.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Tue, May 26, 2026 at 09:00:11PM +0300, Heikki Linnakangas wrote:
> On 18/05/2026 15:14, Bertrand Drouvot wrote:
> > On Wed, May 13, 2026 at 04:20:21PM -0400, Robert Haas wrote:
> > > On Tue, Apr 28, 2026 at 7:17 AM Bertrand Drouvot
> > > <bertranddrouvot.pg@gmail.com> wrote:
> > > > 0003: Add Assert guard to detect permission check before lock regressions
> > > > 
> > > > Add instrumentation under USE_ASSERT_CHECKING to detect cases where object_aclcheck()
> > > > is called on a referenced object before a lock is held on it, which would widen
> > > > the TOCTOU window between the permission check and the dependency recording.
> > > 
> > > I really like the idea of having some kind of cross-check system that
> > > can detect future (or current) coding mistakes.
> > 
> > Thanks for the feedback! BTW, it detected a new one due to 4793fc41f82, so v21
> > attached does fix it to make the CI green.
> 
> I had a closer look at patch 0001.

Thanks!

> It doesn't fix all the problems, we
> definitely need patch 0002/0003 too, but it's a good step forward and I
> think it makes sense to commit it independently. 

Yeah, this will prevent orphaned objects which is a good step forward.

> So I'm focusing on that
> now.

Thanks! I'll resume working on something similar to 0002 and 0003 once 0001 gets
in.

> I noticed we are already doing essentially the same thing for shared
> dependencies, in shdepLockAndCheckObject(). I see that you even copied the
> function comment from shdepLockAndCheckObject() to LockNotPinnedObject(),
> but I didn't see it being otherwise mentioned in this thread. In any case,
> that's a good argument for doing the same for non-shared dependencies that
> we already do for shared dependencies.

Right.

> > +	if (object->classId == RelationRelationId)
> > +	{
> > +		/* skip shared relations as they are pinned */
> > +		if (IsSharedRelation(object->objectId))
> > +			return;
> > +
> > +		/*
> > +		 * We must be in one of the two following cases that would already
> > +		 * prevent the relation to be dropped: 1. The relation is already
> > +		 * locked (could be an existing relation or a relation that we are
> > +		 * creating). 2. The relation is protected indirectly (i.e an index
> > +		 * protected by a lock on its table, a table protected by a lock on a
> > +		 * function that depends of the table...). To avoid any risks, acquire
> > +		 * a lock if there is none. That may add unnecessary lock for 2. but
> > +		 * that's worth it.
> > +		 */
> > +		if (!CheckRelationOidLockedByMe(object->objectId, AccessShareLock, true))
> > +			LockRelationOid(object->objectId, AccessShareLock);
> > +		return;
> > +	}
> 
> Hmm, shouldn't that re-check that the relation exists, after acquiring the
> lock, like the non-relation codepath does? Otherwise it's a little pointless
> to acquire the lock.

Good catch! Your change:

+               if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
+                       return;
+               LockRelationOid(objectId, AccessShareLock);
+
+               if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
+                       return;
+               ereport(ERROR,
+                               (errcode(ERRCODE_UNDEFINED_OBJECT),
+                                errmsg("dependent relation was concurrently dropped")));

Looks good to me.

> I did a bunch of little refactorings and ended up with the attached. Notable
> changes:
> 
> - I renamed and moved LockNotPinnedObject() into
> dependencyLockAndCheckObject(), for consistency with
> shdepLockAndCheckObject().

Makes sense to me.

> - Removed ObjectByIdExist(), inlined it into the caller. The argument to use
> SnapshotSelf or not seemed a bit too special to be generally useful

Yeah, better to have this logic inlined as it will probably not be useful outside
of it.

> - Changed the error message and code to rhyme with the existing "role <OID>
> was concurrently dropped" errors. I didn't add the OID to the error message
> however, because that makes the testing hard.

Agreed that's better.

> - Added a test for a dependency on a role too, to cover the existing
> shdepLockAndCheckObject() function. It's currently disabled because it
> prints the OID, though.

Nit: It also adds:

+# function - role
+permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"

That is not disabled and would already pass without the changes added in 0001.

So I wonder if we could just start by adding this new test (and the XXX one) in
a dedicated patch and then add 0001 that would focus on orphaned stuff only.

A few comments:

1/

+#include "catalog/index.h"

That doesn't look needed.

2/

It looks like pgindent "complains" on pg_depend.c for dependencyLockAndCheckObject().

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-05-27 15:53                                                                       ` Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Heikki Linnakangas @ 2026-05-27 15:53 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Robert Haas <robertmhaas@gmail.com>; Jeff Davis <pgsql@j-davis.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On 26/05/2026 23:18, Bertrand Drouvot wrote:
> On Tue, May 26, 2026 at 09:00:11PM +0300, Heikki Linnakangas wrote:
>> - Added a test for a dependency on a role too, to cover the existing
>> shdepLockAndCheckObject() function. It's currently disabled because it
>> prints the OID, though.
> 
> Nit: It also adds:
> 
> +# function - role
> +permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
> 
> That is not disabled and would already pass without the changes added in 0001.
> 
> So I wonder if we could just start by adding this new test (and the XXX one) in
> a dedicated patch and then add 0001 that would focus on orphaned stuff only.

True, we could do that. It doesn't really seem to me any better or worse 
than just including it in the same commit though.

> A few comments:
> 
> 1/
> 
> +#include "catalog/index.h"
> 
> That doesn't look needed.
> 
> 2/
> 
> It looks like pgindent "complains" on pg_depend.c for dependencyLockAndCheckObject().

Fixed these, and did some more copy-editing on the comments. With that, 
committed and backpatched. Version 14 needed a little more work to 
backport because it didn't have IsPinnedObject(). And I noticed that 
recordDependencyFor() was being called with InvalidOid on ALTER TABLE 
commands on tables with dropped columns. That was bogus but harmless 
before this patch; I fixed that too.

Thanks!

- Heikki






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
@ 2026-06-01 09:21                                                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-03 18:08                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-01 09:21 UTC (permalink / raw)
  To: Heikki Linnakangas <hlinnaka@iki.fi>; +Cc: Robert Haas <robertmhaas@gmail.com>; Jeff Davis <pgsql@j-davis.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, May 27, 2026 at 06:53:35PM +0300, Heikki Linnakangas wrote:
> Fixed these, and did some more copy-editing on the comments. With that,
> committed and backpatched.

Thanks!

Now that we avoid orphaned objects dependencies, I resumed working on Robert's
concern about the TOCTOU window where a REVOKE could land between the original
permission check and the dependency recording.

Based on our discussion during PGConf.dev, PFA a new patch that uses the same
approach as RangeVarGetRelidExtended(): record SharedInvalidMessageCounter at the
time of the original aclcheck, then before locking compare the current counter to
the saved value. If it changed, recheck permission before acquiring the lock.
After the lock wait, if more invalidations arrived, release and retry.

Remarks:

The tracking array lives in a dedicated AclCheckTrackContext memory context
(child of TopMemoryContext). The context is reset at the start of each
top-level utility statement, which frees all prior allocations and provides
clean lifetime management.

Recording is gated by aclcheck_tracking_active, which is set to true only
during top-level utility statement execution. This ensures DML and queries pay
no cost. The flag is cleared both at normal completion of ProcessUtility and in
AbortTransaction to handle the error path.

The patch adds a test that would fail without the TOCTOU protection in place.

Alternatives considered:

- To avoid allocating memory for each statement, keep the array in
TopMemoryContext and never free it (only resetting the count). But that left the
high-water mark allocated for the lifetime of the backend.

- Passing privilege info (roleId, mode) as extra arguments through the
dependency recording APIs (recordDependencyOn, recordMultipleDependencies,
etc.). It was discarded because expression-based dependencies (recordDependencyOnExpr,
find_expr_references_walker) discover objects by walking expression trees: the
caller never sees individual objects and cannot attach privilege info to them.

That's why I believe the tracking approach that is in the attached sounds like
a right approach. Bonus point, it would also help if we want to "ensure" that
we always do the acl check prior the dependency recording: that would avoid
cases like the one mentioned in [1] (for example, when we can create a view and
then record a dependency based on a function we don't have exec privilege on).

[1]: https://postgr.es/m/agsCqlLTytZCudMv%40bdtpg

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v23-0001-Recheck-permissions-after-lock-acquisition-in-de.patch (19.5K, ../../ah1PIyqtT+427dWb@bdtpg/2-v23-0001-Recheck-permissions-after-lock-acquisition-in-de.patch)
  download | inline diff:
From d7e45cac670d05f6c26a3ae006eb8217ef5d5525 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Sat, 30 May 2026 14:35:40 +0000
Subject: [PATCH v23] Recheck permissions after lock acquisition in dependency
 recording

After dependencyLockAndCheckObject() acquires a lock on a referenced object
(which may have blocked on a concurrent DROP), re-verify any permission check
that was done earlier in the statement.  This closes the TOCTOU window where a
REVOKE could land between the original permission check and the dependency
recording.

It uses the same approach as RangeVarGetRelidExtended: record
SharedInvalidMessageCounter at the time of the original aclcheck, then before
locking compare the current counter to the saved value. If it changed, recheck
permission before acquiring the lock. After the lock wait, if more invalidations
arrived, release and retry.

The tracking array lives in a dedicated AclCheckTrackContext memory context
(child of TopMemoryContext). The context is reset at the start of each
top-level utility statement, which frees all prior allocations and provides
clean lifetime management.

Recording is gated by aclcheck_tracking_active, which is set to true only
during top-level utility statement execution. This ensures DML and queries pay
no cost. The flag is cleared both at normal completion of ProcessUtility and in
AbortTransaction to handle the error path.

Alternatives considered:

- To avoid allocating memory for each statements, keep the array in
TopMemoryContext and never free it (only resetting the count). But that left the
high-water mark allocated for the lifetime of the backend.

- Passing privilege info (roleId, mode) as extra arguments through the
  dependency recording APIs (recordDependencyOn, recordMultipleDependencies,
  etc.) was discarded because expression-based dependencies
  (recordDependencyOnExpr, find_expr_references_walker) discover objects by
  walking expression trees: the caller never sees individual objects and cannot
  attach privilege info to them.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/access/transam/xact.c             |   4 +
 src/backend/catalog/aclchk.c                  |  79 +++++++++++++
 src/backend/catalog/pg_depend.c               | 111 ++++++++++++++++--
 src/backend/tcop/utility.c                    |  11 ++
 src/include/catalog/aclcheck_track.h          |  63 ++++++++++
 .../expected/ddl-dependency-locking.out       |  11 +-
 .../specs/ddl-dependency-locking.spec         |  16 +++
 src/tools/pgindent/typedefs.list              |   1 +
 8 files changed, 284 insertions(+), 12 deletions(-)
  62.0% src/backend/catalog/
   3.4% src/backend/tcop/
  19.6% src/include/catalog/
   6.5% src/test/isolation/expected/
   7.1% src/test/isolation/specs/

diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c
index 5586fbe5b07..1a6088bf2f7 100644
--- a/src/backend/access/transam/xact.c
+++ b/src/backend/access/transam/xact.c
@@ -32,6 +32,7 @@
 #include "access/xlogrecovery.h"
 #include "access/xlogutils.h"
 #include "access/xlogwait.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/index.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_enum.h"
@@ -2961,6 +2962,9 @@ AbortTransaction(void)
 	s->parallelModeLevel = 0;
 	s->parallelChildXact = false;	/* should be false already */
 
+	/* Reset aclcheck tracking state */
+	aclcheck_tracking_active = false;
+
 	/*
 	 * do abort processing
 	 */
diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 007ede997c5..07d1a9f0a0f 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -44,6 +44,7 @@
 #include "access/sysattr.h"
 #include "access/tableam.h"
 #include "access/xact.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
@@ -81,9 +82,19 @@
 #include "utils/fmgroids.h"
 #include "utils/guc.h"
 #include "utils/lsyscache.h"
+#include "utils/memutils.h"
 #include "utils/rel.h"
 #include "utils/syscache.h"
 
+#define ACLCHECK_TRACK_INITIAL_SIZE 64
+
+static MemoryContext AclCheckTrackContext = NULL;
+
+AclCheckEntry *aclcheck_tracked = NULL;
+int			aclcheck_tracked_count = 0;
+int			aclcheck_tracked_max = 0;
+bool		aclcheck_tracking_active = false;
+
 /*
  * Internal format used by ALTER DEFAULT PRIVILEGES.
  */
@@ -3891,6 +3902,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4093,6 +4105,7 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5036,3 +5049,69 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Reset the tracking array. Called at each top-level ProcessUtility()
+ * to avoid carrying stale entries from a previous statement.
+ * Resets the memory context, freeing all prior allocations.
+ */
+void
+aclcheck_track_reset(void)
+{
+	if (AclCheckTrackContext == NULL)
+	{
+		AclCheckTrackContext = AllocSetContextCreate(TopMemoryContext,
+													 "AclCheckTrackContext",
+													 ALLOCSET_DEFAULT_SIZES);
+	}
+	else
+	{
+		MemoryContextReset(AclCheckTrackContext);
+	}
+
+	aclcheck_tracked = (AclCheckEntry *)
+		MemoryContextAlloc(AclCheckTrackContext,
+						   ACLCHECK_TRACK_INITIAL_SIZE * sizeof(AclCheckEntry));
+	aclcheck_tracked_max = ACLCHECK_TRACK_INITIAL_SIZE;
+	aclcheck_tracked_count = 0;
+	aclcheck_tracking_active = true;
+}
+
+/*
+ * Grow the tracking array when full. Doubles the size each time.
+ */
+void
+aclcheck_track_grow(void)
+{
+	aclcheck_tracked_max *= 2;
+	aclcheck_tracked = (AclCheckEntry *)
+		repalloc(aclcheck_tracked,
+				 aclcheck_tracked_max * sizeof(AclCheckEntry));
+}
+
+/*
+ * Look up a tracked aclcheck entry for the given object.
+ * Returns true if found, filling in roleId, mode, and inval_count.
+ * Searches from the end to find the most recent check (the one with the
+ * freshest inval_count).
+ *
+ * This is O(n) in the number of tracked entries, but that's fine since a typical
+ * DDL statement should track only a few objects.
+ */
+bool
+aclcheck_track_find(Oid classId, Oid objectId, Oid *roleId, AclMode *mode,
+					uint64 *inval_count)
+{
+	for (int i = aclcheck_tracked_count - 1; i >= 0; i--)
+	{
+		if (aclcheck_tracked[i].classId == classId &&
+			aclcheck_tracked[i].objectId == objectId)
+		{
+			*roleId = aclcheck_tracked[i].roleId;
+			*mode = aclcheck_tracked[i].mode;
+			*inval_count = aclcheck_tracked[i].inval_count;
+			return true;
+		}
+	}
+	return false;
+}
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 9a7a401aced..6b13515bbbc 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -17,6 +17,7 @@
 #include "access/genam.h"
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
@@ -29,6 +30,8 @@
 #include "miscadmin.h"
 #include "storage/lmgr.h"
 #include "storage/lock.h"
+#include "storage/sinval.h"
+#include "utils/acl.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -38,6 +41,7 @@
 
 static bool isObjectPinned(const ObjectAddress *object);
 static void dependencyLockAndCheckObject(Oid classId, Oid objectId);
+static void recheckAclAndLock(Oid classId, Oid objectId);
 
 
 /*
@@ -732,21 +736,104 @@ isObjectPinned(const ObjectAddress *object)
 }
 
 
+/*
+ * recheckAclAndLock()
+ *
+ * Verify permission and acquire lock.
+ *
+ * If a permission check was tracked for this object, compare the saved
+ * SharedInvalidMessageCounter with the current value. If it changed
+ * (meaning catalog invalidations arrived since the original check),
+ * re-verify the permission before locking. After acquiring the lock,
+ * if more invalidations arrived during the wait, release and retry.
+ *
+ * Same approach as RangeVarGetRelidExtended().
+ *
+ * If no permission check was tracked, just acquire the lock.
+ */
+static void
+recheckAclAndLock(Oid classId, Oid objectId)
+{
+	Oid			roleId;
+	AclMode		mode;
+	uint64		saved_inval_count;
+	ObjectAddress object;
+	bool		had_aclcheck;
+
+	had_aclcheck = aclcheck_track_find(classId, objectId,
+									   &roleId, &mode, &saved_inval_count);
+
+	/* No permission check was tracked, just acquire the lock */
+	if (!had_aclcheck)
+	{
+		if (classId == RelationRelationId)
+			LockRelationOid(objectId, AccessShareLock);
+		else
+			LockDatabaseObject(classId, objectId, 0, AccessShareLock);
+		return;
+	}
+
+	object.classId = classId;
+	object.objectId = objectId;
+	object.objectSubId = 0;
+
+	for (;;)
+	{
+		uint64		inval_count;
+
+		inval_count = SharedInvalidMessageCounter;
+
+		/* Recheck only if invalidations arrived since the original check */
+		if (saved_inval_count != inval_count)
+		{
+			AclResult	aclresult;
+
+			if (classId == RelationRelationId)
+				aclresult = pg_class_aclcheck(objectId, roleId, mode);
+			else
+				aclresult = object_aclcheck(classId, objectId, roleId, mode);
+
+			if (aclresult != ACLCHECK_OK)
+				ereport(ERROR,
+						(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
+						 errmsg("permission denied for %s",
+								getObjectDescription(&object, false))));
+		}
+
+		/* Acquire lock */
+		if (classId == RelationRelationId)
+			LockRelationOid(objectId, AccessShareLock);
+		else
+			LockDatabaseObject(classId, objectId, 0, AccessShareLock);
+
+		/* If no invalidations during lock wait, we're done */
+		if (inval_count == SharedInvalidMessageCounter)
+			break;
+
+		/* Something changed, release lock and retry */
+		if (classId == RelationRelationId)
+			UnlockRelationOid(objectId, AccessShareLock);
+		else
+			UnlockDatabaseObject(classId, objectId, 0, AccessShareLock);
+
+		saved_inval_count = 0;	/* force recheck on next iteration */
+	}
+}
+
+
 /*
  * dependencyLockAndCheckObject
  *
  * Lock the object that we are about to record a dependency on.  After it's
  * locked, verify that it hasn't been dropped while we weren't looking.  If it
- * has been dropped, throw an an error.
+ * has been dropped, throw an error.
+ *
+ * Lock acquisition and permission verification are handled by
+ * recheckAclAndLock(), which uses the same retry pattern as
+ * RangeVarGetRelidExtended() to close the TOCTOU window.
  *
  * If the caller already holds a lock that conflicts with DROP
- * (AccessShareLock or stronger), this does nothing.  Callers should acquire
- * locks already when they look up the referenced objects, but many callers
- * currently do not.  This is a backstop to make sure that we don't record a
- * bogus reference permanently in the catalogs in that case.  In the future,
- * after we have tightened up all the callers to acquire locks earlier, this
- * could just verify that the object is already locked and throw an error if
- * not.
+ * (AccessShareLock or stronger), this skips lock acquisition entirely.
  */
 static void
 dependencyLockAndCheckObject(Oid classId, Oid objectId)
@@ -775,8 +862,8 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		if (LockHeldByMe(&tag, AccessShareLock, true))
 			return;
 
-		/* Assume we should lock the whole object not a sub-object */
-		LockDatabaseObject(classId, objectId, 0, AccessShareLock);
+		/* Check permission and acquire lock using retry pattern */
+		recheckAclAndLock(classId, objectId);
 
 		/*
 		 * Check that the object still exists.  If the catalog has a suitable
@@ -835,7 +922,9 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 
 		if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
 			return;
-		LockRelationOid(objectId, AccessShareLock);
+
+		/* Check permission and acquire lock using retry pattern */
+		recheckAclAndLock(classId, objectId);
 
 		if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
 			return;
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..cc72c616657 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -20,6 +20,7 @@
 #include "access/twophase.h"
 #include "access/xact.h"
 #include "access/xlog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
@@ -515,6 +516,13 @@ ProcessUtility(PlannedStmt *pstmt,
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
+	/*
+	 * Reset the aclcheck tracking for each top-level utility statement and
+	 * enable tracking for the duration of the statement.
+	 */
+	if (context == PROCESS_UTILITY_TOPLEVEL)
+		aclcheck_track_reset();
+
 	/*
 	 * We provide a function hook variable that lets loadable plugins get
 	 * control when ProcessUtility is called.  Such a plugin would normally
@@ -528,6 +536,9 @@ ProcessUtility(PlannedStmt *pstmt,
 		standard_ProcessUtility(pstmt, queryString, readOnlyTree,
 								context, params, queryEnv,
 								dest, qc);
+
+	if (context == PROCESS_UTILITY_TOPLEVEL)
+		aclcheck_tracking_active = false;
 }
 
 /*
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..86880f7b56f
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,63 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Track permission checks for revalidation after lock acquisition
+ *	  in dependencyLockAndCheckObject().
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#include "storage/sinval.h"
+#include "utils/acl.h"
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+	Oid			roleId;
+	AclMode		mode;
+	uint64		inval_count;
+} AclCheckEntry;
+
+extern AclCheckEntry *aclcheck_tracked;
+extern int	aclcheck_tracked_count;
+extern int	aclcheck_tracked_max;
+extern bool aclcheck_tracking_active;
+
+extern void aclcheck_track_reset(void);
+extern void aclcheck_track_grow(void);
+extern bool aclcheck_track_find(Oid classId, Oid objectId,
+								Oid *roleId, AclMode *mode,
+								uint64 *inval_count);
+
+/*
+ * Record an aclcheck for later revalidation.
+ *
+ * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Only records when inside an utility statement.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+{
+	if (!aclcheck_tracking_active)
+		return;
+
+	if (aclcheck_tracked_count >= aclcheck_tracked_max)
+		aclcheck_track_grow();
+
+	aclcheck_tracked[aclcheck_tracked_count].classId = classId;
+	aclcheck_tracked[aclcheck_tracked_count].objectId = objectId;
+	aclcheck_tracked[aclcheck_tracked_count].roleId = roleId;
+	aclcheck_tracked[aclcheck_tracked_count].mode = mode;
+	aclcheck_tracked[aclcheck_tracked_count].inval_count = SharedInvalidMessageCounter;
+	aclcheck_tracked_count++;
+}
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/test/isolation/expected/ddl-dependency-locking.out b/src/test/isolation/expected/ddl-dependency-locking.out
index 636de281022..002d537efb7 100644
--- a/src/test/isolation/expected/ddl-dependency-locking.out
+++ b/src/test/isolation/expected/ddl-dependency-locking.out
@@ -1,4 +1,4 @@
-Parsed test spec with 2 sessions
+Parsed test spec with 3 sessions
 
 starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
 step s1_begin: BEGIN;
@@ -135,3 +135,12 @@ step s2_drop_role: DROP ROLE regress_dependency; <waiting ...>
 step s1_commit: COMMIT;
 step s2_drop_role: <... completed>
 ERROR:  role "regress_dependency" cannot be dropped because some objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_as_role_user s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_as_role_user: SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_as_role_user: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_wrapper
diff --git a/src/test/isolation/specs/ddl-dependency-locking.spec b/src/test/isolation/specs/ddl-dependency-locking.spec
index de5bd88d35e..69e6fedf9f5 100644
--- a/src/test/isolation/specs/ddl-dependency-locking.spec
+++ b/src/test/isolation/specs/ddl-dependency-locking.spec
@@ -11,6 +11,10 @@ setup
 	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+	CREATE ROLE role_fdw;
+	CREATE ROLE role_user LOGIN;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_wrapper TO role_fdw;
+	GRANT role_fdw TO role_user;
 	CREATE ROLE regress_dependency;
 }
 
@@ -24,6 +28,7 @@ teardown
 	DROP FUNCTION IF EXISTS alterschema.falter();
 	DROP DOMAIN IF EXISTS idid;
 	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP SERVER IF EXISTS srv_role_revoked;
 	DROP TABLE IF EXISTS tabtype;
 	DROP SCHEMA IF EXISTS testschema;
 	DROP SCHEMA IF EXISTS alterschema;
@@ -32,6 +37,8 @@ teardown
 	DROP DOMAIN IF EXISTS id;
 	DROP FUNCTION IF EXISTS f();
 	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+	DROP ROLE IF EXISTS role_user;
+	DROP ROLE IF EXISTS role_fdw;
 	DROP ROLE regress_dependency;
 }
 
@@ -47,6 +54,7 @@ step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alte
 step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
 step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
 step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_create_server_as_role_user" { SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; }
 step "s1_commit" { COMMIT; }
 
 session "s2"
@@ -62,6 +70,11 @@ step "s2_drop_domain_id" { DROP DOMAIN id; }
 step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
 step "s2_drop_role" { DROP ROLE regress_dependency; }
 step "s2_commit" { COMMIT; }
+step "s2_rollback" { ROLLBACK; }
+
+session "s3"
+
+step "s3_revoke_role" { REVOKE role_fdw FROM role_user; }
 
 # create function - drop schema
 permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
@@ -102,3 +115,6 @@ permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
 # <OID> was concurrently dropped", contains an OID that is not stable.
 #
 # permutation "s2_begin" "s2_drop_role" "s1_alter_function_owner" "s2_commit"
+
+# Role membership TOCTOU: permission via role revoked during lock wait.
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_as_role_user" "s3_revoke_role" "s2_rollback"
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index 8cf40c87043..cb0cc25bda8 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -19,6 +19,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-03 18:08                                                                           ` Jeff Davis <pgsql@j-davis.com>
  2026-06-04 17:17                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2026-06-03 18:08 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Heikki Linnakangas <hlinnaka@iki.fi>; +Cc: Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Mon, 2026-06-01 at 09:21 +0000, Bertrand Drouvot wrote:
> Now that we avoid orphaned objects dependencies, I resumed working on
> Robert's
> concern about the TOCTOU window where a REVOKE could land between the
> original
> permission check and the dependency recording.
> 
> Based on our discussion during PGConf.dev, PFA a new patch that uses
> the same
> approach as RangeVarGetRelidExtended(): record
> SharedInvalidMessageCounter at the
> time of the original aclcheck, then before locking compare the
> current counter to
> the saved value. If it changed, recheck permission before acquiring
> the lock.
> After the lock wait, if more invalidations arrived, release and
> retry.

RangeVarGetRelidExtended() coordinates three things:

  - name lookup
  - lock
  - ACL check

whereas recheckAclAndLock() only coordinates the latter two. That means
there can still be some strange failures, like:

  -- Session 1
  BEGIN;
  DROP SCHEMA s2;

  -- Session 2
  SET search_path=s2, s1;
  CREATE FUNCTION f() RETURNS INT LANGUAGE plpgsql AS
    $$ BEGIN RETURN 42; END; $$;

  -- Session 1
  COMMIT;

  -- Session 2
  ERROR:  referenced schema was concurrently dropped

even though no schema was actually referenced in the query, and a retry
of the transaction successfully creates the function in s1. Is that
expected?

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-03 18:08                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-04 17:17                                                                             ` Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:12                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2026-06-04 17:17 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Heikki Linnakangas <hlinnaka@iki.fi>; +Cc: Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Wed, 2026-06-03 at 11:08 -0700, Jeff Davis wrote:
> RangeVarGetRelidExtended() coordinates three things:
> 
>   - name lookup
>   - lock
>   - ACL check
> 
> whereas recheckAclAndLock() only coordinates the latter two.

Given that we don't do another name lookup, the object Oid doesn't
change, and it's not obvious why we need a loop in this path.

A sequence like:

Earlier during DDL processing:
  0. Name lookup and ACL check (and track ACLs)

When recording dependencies:
  1. Lock object
  2. Check that it still exists, error if not
  3. recheck tracked ACLs, error if failure

could work too, right?

I see why you might want to do the checks while not holding the lock,
but it doesn't seem like a requirement (if the user doesn't have
permissions it should fail quickly and release). In any case, it's
worth a comment explaining why the loop is there.

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-03 18:08                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-04 17:17                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-05 13:12                                                                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-05 13:12 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jun 04, 2026 at 10:17:57AM -0700, Jeff Davis wrote:
> Given that we don't do another name lookup, the object Oid doesn't
> change, and it's not obvious why we need a loop in this path.
> 
> A sequence like:
> 
> Earlier during DDL processing:
>   0. Name lookup and ACL check (and track ACLs)
> 
> When recording dependencies:
>   1. Lock object
>   2. Check that it still exists, error if not
>   3. recheck tracked ACLs, error if failure
> 
> could work too, right?

Yeah, that's a good point, thanks!

> I see why you might want to do the checks while not holding the lock,
> but it doesn't seem like a requirement (if the user doesn't have
> permissions it should fail quickly and release).

I agree that we can get rid of the loop and that's what v24 shared up-thread [1]
is now implementing. The downside is that one could take a lock on an object
he has no privileges on but then, as you said, it will be released shortly after.

[1]: https://postgr.es/m/aiLKkTC6QBt8i35P%40bdtpg

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-04 17:03                                                                           ` Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2026-06-04 17:03 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Heikki Linnakangas <hlinnaka@iki.fi>; +Cc: Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Mon, 2026-06-01 at 09:21 +0000, Bertrand Drouvot wrote:
> The tracking array lives in a dedicated AclCheckTrackContext memory
> context
> (child of TopMemoryContext). The context is reset at the start of
> each
> top-level utility statement, which frees all prior allocations and
> provides
> clean lifetime management.
> 
> Recording is gated by aclcheck_tracking_active, which is set to true
> only
> during top-level utility statement execution. This ensures DML and
> queries pay
> no cost. The flag is cleared both at normal completion of
> ProcessUtility and in
> AbortTransaction to handle the error path.

This could use some better high-level comments in the code. Something
like:

"DDL performs ACL checks on referenced objects before acquiring a lock
on them. The lock is acquired much later, when recording dependencies.
Track the ACL checks, so that we can re-check them after acquiring the
lock. XXX: consider refactoring so that we perform the name lookup,
acquire the lock, and check ACLs all in unison, like
RangeVarGetRelidExtended()."

Assuming I understand correctly.

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-05 13:09                                                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-05 13:09 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jun 04, 2026 at 10:03:22AM -0700, Jeff Davis wrote:
> On Mon, 2026-06-01 at 09:21 +0000, Bertrand Drouvot wrote:
> > The tracking array lives in a dedicated AclCheckTrackContext memory
> > context
> > (child of TopMemoryContext). The context is reset at the start of
> > each
> > top-level utility statement, which frees all prior allocations and
> > provides
> > clean lifetime management.
> > 
> > Recording is gated by aclcheck_tracking_active, which is set to true
> > only
> > during top-level utility statement execution. This ensures DML and
> > queries pay
> > no cost. The flag is cleared both at normal completion of
> > ProcessUtility and in
> > AbortTransaction to handle the error path.
> 
> This could use some better high-level comments in the code. Something
> like:
> 
> "DDL performs ACL checks on referenced objects before acquiring a lock
> on them. The lock is acquired much later, when recording dependencies.
> Track the ACL checks, so that we can re-check them after acquiring the
> lock.

Agreed, I just re-worded a bit to add some nuance in v24 attached, as:

"
may perform ACL checks on referenced objects without first holding a lock on
them. In that case, the lock is acquired much later, when recording the
dependencies. Track the ACL checks, so that we can re-check them after acquiring
the lock while recording dependencies."

> XXX: consider refactoring so that we perform the name lookup,
> acquire the lock, and check ACLs all in unison, like
> RangeVarGetRelidExtended()."

I like the XXX, as I agree that what you mentioned in [1] is an area of improvement
but not something directly linked to the TOCTOU issue that this patch is addressing.

FWIW, with the scenario you described in [1]:

- before 2fbb21170e9, the function would be linked to a non existing schema
- with 2fbb21170e9, it produces "ERROR:  referenced schema was concurrently dropped"

the current patch just "keep" the post 2fbb21170e9 behavior.

[1]: https://postgr.es/m/5315d15a42109297259d1a3264ad09e363eb98df.camel%40j-davis.com

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v24-0001-Recheck-permissions-after-lock-acquisition-in-de.patch (20.3K, ../../aiLKkTC6QBt8i35P@bdtpg/2-v24-0001-Recheck-permissions-after-lock-acquisition-in-de.patch)
  download | inline diff:
From 3254bd8050b4849bb9fd5754faa23ee47272cdda Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Sat, 30 May 2026 14:35:40 +0000
Subject: [PATCH v24] Recheck permissions after lock acquisition in dependency
 recording

After dependencyLockAndCheckObject() acquires a lock on a referenced object
(which may have blocked on a concurrent DROP), re-verify any permission check
that was done earlier in the statement.  This closes the TOCTOU window where a
REVOKE could land between the original permission check and the dependency
recording.

The approach: record SharedInvalidMessageCounter at the time of the original
aclcheck. After acquiring the lock and verifying the object still exists,
compare the saved counter with the current value.  If it changed (meaning
catalog invalidations arrived since the original check), re-verify the
permission. Since the OID is fixed (no name re-resolution), a failure is
definitive and no retry loop is needed.

The tracking array lives in a dedicated AclCheckTrackContext memory context
(child of TopMemoryContext). The context is reset at the start of each
top-level utility statement, which frees all prior allocations and provides
clean lifetime management.

Recording is gated by aclcheck_tracking_active, which is set to true only
during top-level utility statement execution. This ensures DML and queries pay
no cost. The flag is cleared both at normal completion of ProcessUtility and in
AbortTransaction to handle the error path.

Alternatives considered:

- To avoid allocating memory for each statements, keep the array in
TopMemoryContext and never free it (only resetting the count). But that left the
high-water mark allocated for the lifetime of the backend.

- Passing privilege info (roleId, mode) as extra arguments through the
  dependency recording APIs (recordDependencyOn, recordMultipleDependencies,
  etc.) was discarded because expression-based dependencies
  (recordDependencyOnExpr, find_expr_references_walker) discover objects by
  walking expression trees: the caller never sees individual objects and cannot
  attach privilege info to them.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/access/transam/xact.c             |   4 +
 src/backend/catalog/aclchk.c                  |  79 +++++++++++++
 src/backend/catalog/pg_depend.c               | 109 ++++++++++++++----
 src/backend/tcop/utility.c                    |  11 ++
 src/include/catalog/aclcheck_track.h          |  72 ++++++++++++
 .../expected/ddl-dependency-locking.out       |  11 +-
 .../specs/ddl-dependency-locking.spec         |  16 +++
 src/tools/pgindent/typedefs.list              |   1 +
 8 files changed, 282 insertions(+), 21 deletions(-)
  58.0% src/backend/catalog/
   3.3% src/backend/tcop/
  23.8% src/include/catalog/
   6.4% src/test/isolation/expected/
   7.0% src/test/isolation/specs/

diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c
index 5586fbe5b07..1a6088bf2f7 100644
--- a/src/backend/access/transam/xact.c
+++ b/src/backend/access/transam/xact.c
@@ -32,6 +32,7 @@
 #include "access/xlogrecovery.h"
 #include "access/xlogutils.h"
 #include "access/xlogwait.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/index.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_enum.h"
@@ -2961,6 +2962,9 @@ AbortTransaction(void)
 	s->parallelModeLevel = 0;
 	s->parallelChildXact = false;	/* should be false already */
 
+	/* Reset aclcheck tracking state */
+	aclcheck_tracking_active = false;
+
 	/*
 	 * do abort processing
 	 */
diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 007ede997c5..07d1a9f0a0f 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -44,6 +44,7 @@
 #include "access/sysattr.h"
 #include "access/tableam.h"
 #include "access/xact.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
@@ -81,9 +82,19 @@
 #include "utils/fmgroids.h"
 #include "utils/guc.h"
 #include "utils/lsyscache.h"
+#include "utils/memutils.h"
 #include "utils/rel.h"
 #include "utils/syscache.h"
 
+#define ACLCHECK_TRACK_INITIAL_SIZE 64
+
+static MemoryContext AclCheckTrackContext = NULL;
+
+AclCheckEntry *aclcheck_tracked = NULL;
+int			aclcheck_tracked_count = 0;
+int			aclcheck_tracked_max = 0;
+bool		aclcheck_tracking_active = false;
+
 /*
  * Internal format used by ALTER DEFAULT PRIVILEGES.
  */
@@ -3891,6 +3902,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4093,6 +4105,7 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5036,3 +5049,69 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Reset the tracking array. Called at each top-level ProcessUtility()
+ * to avoid carrying stale entries from a previous statement.
+ * Resets the memory context, freeing all prior allocations.
+ */
+void
+aclcheck_track_reset(void)
+{
+	if (AclCheckTrackContext == NULL)
+	{
+		AclCheckTrackContext = AllocSetContextCreate(TopMemoryContext,
+													 "AclCheckTrackContext",
+													 ALLOCSET_DEFAULT_SIZES);
+	}
+	else
+	{
+		MemoryContextReset(AclCheckTrackContext);
+	}
+
+	aclcheck_tracked = (AclCheckEntry *)
+		MemoryContextAlloc(AclCheckTrackContext,
+						   ACLCHECK_TRACK_INITIAL_SIZE * sizeof(AclCheckEntry));
+	aclcheck_tracked_max = ACLCHECK_TRACK_INITIAL_SIZE;
+	aclcheck_tracked_count = 0;
+	aclcheck_tracking_active = true;
+}
+
+/*
+ * Grow the tracking array when full. Doubles the size each time.
+ */
+void
+aclcheck_track_grow(void)
+{
+	aclcheck_tracked_max *= 2;
+	aclcheck_tracked = (AclCheckEntry *)
+		repalloc(aclcheck_tracked,
+				 aclcheck_tracked_max * sizeof(AclCheckEntry));
+}
+
+/*
+ * Look up a tracked aclcheck entry for the given object.
+ * Returns true if found, filling in roleId, mode, and inval_count.
+ * Searches from the end to find the most recent check (the one with the
+ * freshest inval_count).
+ *
+ * This is O(n) in the number of tracked entries, but that's fine since a typical
+ * DDL statement should track only a few objects.
+ */
+bool
+aclcheck_track_find(Oid classId, Oid objectId, Oid *roleId, AclMode *mode,
+					uint64 *inval_count)
+{
+	for (int i = aclcheck_tracked_count - 1; i >= 0; i--)
+	{
+		if (aclcheck_tracked[i].classId == classId &&
+			aclcheck_tracked[i].objectId == objectId)
+		{
+			*roleId = aclcheck_tracked[i].roleId;
+			*mode = aclcheck_tracked[i].mode;
+			*inval_count = aclcheck_tracked[i].inval_count;
+			return true;
+		}
+	}
+	return false;
+}
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 9a7a401aced..bc56d39d8bd 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -17,6 +17,7 @@
 #include "access/genam.h"
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
@@ -29,6 +30,8 @@
 #include "miscadmin.h"
 #include "storage/lmgr.h"
 #include "storage/lock.h"
+#include "storage/sinval.h"
+#include "utils/acl.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -38,6 +41,7 @@
 
 static bool isObjectPinned(const ObjectAddress *object);
 static void dependencyLockAndCheckObject(Oid classId, Oid objectId);
+static void recheckAcl(Oid classId, Oid objectId);
 
 
 /*
@@ -732,21 +736,70 @@ isObjectPinned(const ObjectAddress *object)
 }
 
 
+/*
+ * recheckAcl()
+ *
+ * Re-verify a tracked permission check on the given object.
+ *
+ * Called after acquiring the lock and verifying the object still exists.
+ * If a permission check was tracked for this object and catalog
+ * invalidations arrived since the original check, re-verify the permission.
+ * This closes the TOCTOU window where a REVOKE could land between the
+ * original permission check and the dependency recording.
+ *
+ * Since we don't re-resolve names (the OID is fixed), there is no need for
+ * a retry loop here. If the recheck fails, it's a definitive failure.
+ */
+static void
+recheckAcl(Oid classId, Oid objectId)
+{
+	Oid			roleId;
+	AclMode		mode;
+	uint64		saved_inval_count;
+	bool		had_aclcheck;
+
+	had_aclcheck = aclcheck_track_find(classId, objectId,
+									   &roleId, &mode, &saved_inval_count);
+
+	if (!had_aclcheck)
+		return;
+
+	/* Recheck only if invalidations arrived since the original check */
+	if (saved_inval_count != SharedInvalidMessageCounter)
+	{
+		AclResult	aclresult;
+
+		if (classId == RelationRelationId)
+			aclresult = pg_class_aclcheck(objectId, roleId, mode);
+		else
+			aclresult = object_aclcheck(classId, objectId, roleId, mode);
+
+		if (aclresult != ACLCHECK_OK)
+		{
+			ObjectAddress object;
+
+			object.classId = classId;
+			object.objectId = objectId;
+			object.objectSubId = 0;
+			ereport(ERROR,
+					(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
+					 errmsg("permission denied for %s",
+							getObjectDescription(&object, false))));
+		}
+	}
+}
+
+
 /*
  * dependencyLockAndCheckObject
  *
- * Lock the object that we are about to record a dependency on.  After it's
- * locked, verify that it hasn't been dropped while we weren't looking.  If it
- * has been dropped, throw an an error.
+ * Lock the object that we are about to record a dependency on. After it's
+ * locked, verify that it hasn't been dropped while we weren't looking. If it
+ * has been dropped, throw an error. Then re-verify any tracked permission
+ * check to close the TOCTOU window.
  *
  * If the caller already holds a lock that conflicts with DROP
- * (AccessShareLock or stronger), this does nothing.  Callers should acquire
- * locks already when they look up the referenced objects, but many callers
- * currently do not.  This is a backstop to make sure that we don't record a
- * bogus reference permanently in the catalogs in that case.  In the future,
- * after we have tightened up all the callers to acquire locks earlier, this
- * could just verify that the object is already locked and throw an error if
- * not.
+ * (AccessShareLock or stronger), this skips lock acquisition entirely.
  */
 static void
 dependencyLockAndCheckObject(Oid classId, Oid objectId)
@@ -773,20 +826,25 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 						   0);
 
 		if (LockHeldByMe(&tag, AccessShareLock, true))
+		{
+			/* Recheck ACL */
+			recheckAcl(classId, objectId);
 			return;
+		}
 
-		/* Assume we should lock the whole object not a sub-object */
+		/* Acquire lock */
 		LockDatabaseObject(classId, objectId, 0, AccessShareLock);
 
-		/*
-		 * Check that the object still exists.  If the catalog has a suitable
-		 * syscache, check that first.
-		 */
+		/* Check that the object still exists */
 		cache = get_object_catcache_oid(classId);
 		if (cache != SYSCACHEID_INVALID)
 		{
 			if (SearchSysCacheExists1(cache, ObjectIdGetDatum(objectId)))
+			{
+				/* Recheck ACL */
+				recheckAcl(classId, objectId);
 				return;
+			}
 		}
 
 		/*
@@ -814,6 +872,9 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 
 		systable_endscan(scan);
 		table_close(rel, AccessShareLock);
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 	else
 	{
@@ -834,14 +895,22 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		Assert(!IsSharedRelation(objectId));
 
 		if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
+		{
+			recheckAcl(classId, objectId);
 			return;
+		}
+
+		/* Acquire lock */
 		LockRelationOid(objectId, AccessShareLock);
 
-		if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
-			return;
-		ereport(ERROR,
-				(errcode(ERRCODE_UNDEFINED_OBJECT),
-				 errmsg("referenced relation was concurrently dropped")));
+		/* Check that the object still exists */
+		if (!SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
+			ereport(ERROR,
+					(errcode(ERRCODE_UNDEFINED_OBJECT),
+					 errmsg("referenced relation was concurrently dropped")));
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 }
 
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..cc72c616657 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -20,6 +20,7 @@
 #include "access/twophase.h"
 #include "access/xact.h"
 #include "access/xlog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
@@ -515,6 +516,13 @@ ProcessUtility(PlannedStmt *pstmt,
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
+	/*
+	 * Reset the aclcheck tracking for each top-level utility statement and
+	 * enable tracking for the duration of the statement.
+	 */
+	if (context == PROCESS_UTILITY_TOPLEVEL)
+		aclcheck_track_reset();
+
 	/*
 	 * We provide a function hook variable that lets loadable plugins get
 	 * control when ProcessUtility is called.  Such a plugin would normally
@@ -528,6 +536,9 @@ ProcessUtility(PlannedStmt *pstmt,
 		standard_ProcessUtility(pstmt, queryString, readOnlyTree,
 								context, params, queryEnv,
 								dest, qc);
+
+	if (context == PROCESS_UTILITY_TOPLEVEL)
+		aclcheck_tracking_active = false;
 }
 
 /*
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..7d845076ed5
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,72 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Track permission checks for revalidation after lock acquisition
+ *	  in dependencyLockAndCheckObject().
+ *
+ * DDL may perform ACL checks on referenced objects without first holding a lock
+ * on them. In that case, the lock is acquired much later, when recording
+ * dependencies.
+ * Track the ACL checks, so that we can re-check them after acquiring the
+ * lock while recording dependencies.
+ *
+ * XXX: consider refactoring so that we perform the name lookup, acquire the
+ * lock, and check ACLs all in unison, like RangeVarGetRelidExtended().
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#include "storage/sinval.h"
+#include "utils/acl.h"
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+	Oid			roleId;
+	AclMode		mode;
+	uint64		inval_count;
+} AclCheckEntry;
+
+extern AclCheckEntry *aclcheck_tracked;
+extern int	aclcheck_tracked_count;
+extern int	aclcheck_tracked_max;
+extern bool aclcheck_tracking_active;
+
+extern void aclcheck_track_reset(void);
+extern void aclcheck_track_grow(void);
+extern bool aclcheck_track_find(Oid classId, Oid objectId,
+								Oid *roleId, AclMode *mode,
+								uint64 *inval_count);
+
+/*
+ * Record an aclcheck for later revalidation.
+ *
+ * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Only records when inside an utility statement.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+{
+	if (!aclcheck_tracking_active)
+		return;
+
+	if (aclcheck_tracked_count >= aclcheck_tracked_max)
+		aclcheck_track_grow();
+
+	aclcheck_tracked[aclcheck_tracked_count].classId = classId;
+	aclcheck_tracked[aclcheck_tracked_count].objectId = objectId;
+	aclcheck_tracked[aclcheck_tracked_count].roleId = roleId;
+	aclcheck_tracked[aclcheck_tracked_count].mode = mode;
+	aclcheck_tracked[aclcheck_tracked_count].inval_count = SharedInvalidMessageCounter;
+	aclcheck_tracked_count++;
+}
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/test/isolation/expected/ddl-dependency-locking.out b/src/test/isolation/expected/ddl-dependency-locking.out
index 636de281022..002d537efb7 100644
--- a/src/test/isolation/expected/ddl-dependency-locking.out
+++ b/src/test/isolation/expected/ddl-dependency-locking.out
@@ -1,4 +1,4 @@
-Parsed test spec with 2 sessions
+Parsed test spec with 3 sessions
 
 starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
 step s1_begin: BEGIN;
@@ -135,3 +135,12 @@ step s2_drop_role: DROP ROLE regress_dependency; <waiting ...>
 step s1_commit: COMMIT;
 step s2_drop_role: <... completed>
 ERROR:  role "regress_dependency" cannot be dropped because some objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_as_role_user s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_as_role_user: SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_as_role_user: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_wrapper
diff --git a/src/test/isolation/specs/ddl-dependency-locking.spec b/src/test/isolation/specs/ddl-dependency-locking.spec
index de5bd88d35e..69e6fedf9f5 100644
--- a/src/test/isolation/specs/ddl-dependency-locking.spec
+++ b/src/test/isolation/specs/ddl-dependency-locking.spec
@@ -11,6 +11,10 @@ setup
 	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+	CREATE ROLE role_fdw;
+	CREATE ROLE role_user LOGIN;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_wrapper TO role_fdw;
+	GRANT role_fdw TO role_user;
 	CREATE ROLE regress_dependency;
 }
 
@@ -24,6 +28,7 @@ teardown
 	DROP FUNCTION IF EXISTS alterschema.falter();
 	DROP DOMAIN IF EXISTS idid;
 	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP SERVER IF EXISTS srv_role_revoked;
 	DROP TABLE IF EXISTS tabtype;
 	DROP SCHEMA IF EXISTS testschema;
 	DROP SCHEMA IF EXISTS alterschema;
@@ -32,6 +37,8 @@ teardown
 	DROP DOMAIN IF EXISTS id;
 	DROP FUNCTION IF EXISTS f();
 	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+	DROP ROLE IF EXISTS role_user;
+	DROP ROLE IF EXISTS role_fdw;
 	DROP ROLE regress_dependency;
 }
 
@@ -47,6 +54,7 @@ step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alte
 step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
 step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
 step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_create_server_as_role_user" { SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; }
 step "s1_commit" { COMMIT; }
 
 session "s2"
@@ -62,6 +70,11 @@ step "s2_drop_domain_id" { DROP DOMAIN id; }
 step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
 step "s2_drop_role" { DROP ROLE regress_dependency; }
 step "s2_commit" { COMMIT; }
+step "s2_rollback" { ROLLBACK; }
+
+session "s3"
+
+step "s3_revoke_role" { REVOKE role_fdw FROM role_user; }
 
 # create function - drop schema
 permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
@@ -102,3 +115,6 @@ permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
 # <OID> was concurrently dropped", contains an OID that is not stable.
 #
 # permutation "s2_begin" "s2_drop_role" "s1_alter_function_owner" "s2_commit"
+
+# Role membership TOCTOU: permission via role revoked during lock wait.
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_as_role_user" "s3_revoke_role" "s2_rollback"
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index 8cf40c87043..cb0cc25bda8 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -19,6 +19,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-08 21:55                                                                               ` Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2026-06-08 21:55 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Fri, 2026-06-05 at 13:09 +0000, Bertrand Drouvot wrote:
> the current patch

  /*
   * Look up a tracked aclcheck entry for the given object.
   * Returns true if found, filling in roleId, mode, and inval_count.
   * Searches from the end to find the most recent check (the one with
the
   * freshest inval_count).

What if two tracked ACL checks had different modes? Don't you need to
do both checks or somehow combine the modes in the tracking entry?

(I'm not sure if this is a practical problem or not.)

Regards,
	Jeff Davis







^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-09 06:47                                                                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 18:04                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-09 06:47 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Mon, Jun 08, 2026 at 02:55:19PM -0700, Jeff Davis wrote:
> On Fri, 2026-06-05 at 13:09 +0000, Bertrand Drouvot wrote:
> > the current patch
> 
>   /*
>    * Look up a tracked aclcheck entry for the given object.
>    * Returns true if found, filling in roleId, mode, and inval_count.
>    * Searches from the end to find the most recent check (the one with
> the
>    * freshest inval_count).
> 
> What if two tracked ACL checks had different modes? Don't you need to
> do both checks or somehow combine the modes in the tracking entry?
> 
> (I'm not sure if this is a practical problem or not.)

Humm, good point. I was focusing on a "full" role revoke but maybe what you
describe could be a practical problem (in case of privilege revoke from the
role).

In order to be on the safe side of things, the attached now iterates through all
matching entries (and not only the last one). It's still a flat array as its
linear scan is O(n) in the number of tracked entries, but that's fine since a
typical DDL statement tracks only a few objects.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v25-0001-Recheck-permissions-after-lock-acquisition-in-de.patch (19.7K, ../../aie26jMSoEMrHLaI@bdtpg/2-v25-0001-Recheck-permissions-after-lock-acquisition-in-de.patch)
  download | inline diff:
From 6f5968b39b3f945c60dc00dd24614e2ebe082a53 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Sat, 30 May 2026 14:35:40 +0000
Subject: [PATCH v25] Recheck permissions after lock acquisition in dependency
 recording

After dependencyLockAndCheckObject() acquires a lock on a referenced object
(which may have blocked on a concurrent DROP), re-verify any permission check
that was done earlier in the statement.  This closes the TOCTOU window where a
REVOKE could land between the original permission check and the dependency
recording.

The approach: record SharedInvalidMessageCounter at the time of the original
aclcheck. After acquiring the lock and verifying the object still exists,
compare the saved counter with the current value.  If it changed (meaning
catalog invalidations arrived since the original check), re-verify the
permission. Since the OID is fixed (no name re-resolution), a failure is
definitive and no retry loop is needed.

The tracking array lives in a dedicated AclCheckTrackContext memory context
(child of TopMemoryContext). The context is reset at the start of each
top-level utility statement, which frees all prior allocations and provides
clean lifetime management.

Recording is gated by aclcheck_tracking_active, which is set to true only
during top-level utility statement execution. This ensures DML and queries pay
no cost. The flag is cleared both at normal completion of ProcessUtility and in
AbortTransaction to handle the error path.

Alternatives considered:

- To avoid allocating memory for each statements, keep the array in
TopMemoryContext and never free it (only resetting the count). But that left the
high-water mark allocated for the lifetime of the backend.

- Passing privilege info (roleId, mode) as extra arguments through the
  dependency recording APIs (recordDependencyOn, recordMultipleDependencies,
  etc.) was discarded because expression-based dependencies
  (recordDependencyOnExpr, find_expr_references_walker) discover objects by
  walking expression trees: the caller never sees individual objects and cannot
  attach privilege info to them.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/access/transam/xact.c             |   4 +
 src/backend/catalog/aclchk.c                  |  52 ++++++++
 src/backend/catalog/pg_depend.c               | 113 ++++++++++++++----
 src/backend/tcop/utility.c                    |  11 ++
 src/include/catalog/aclcheck_track.h          |  69 +++++++++++
 .../expected/ddl-dependency-locking.out       |  11 +-
 .../specs/ddl-dependency-locking.spec         |  16 +++
 src/tools/pgindent/typedefs.list              |   1 +
 8 files changed, 256 insertions(+), 21 deletions(-)
  56.6% src/backend/catalog/
   3.5% src/backend/tcop/
  24.0% src/include/catalog/
   6.8% src/test/isolation/expected/
   7.4% src/test/isolation/specs/

diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c
index 5586fbe5b07..1a6088bf2f7 100644
--- a/src/backend/access/transam/xact.c
+++ b/src/backend/access/transam/xact.c
@@ -32,6 +32,7 @@
 #include "access/xlogrecovery.h"
 #include "access/xlogutils.h"
 #include "access/xlogwait.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/index.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_enum.h"
@@ -2961,6 +2962,9 @@ AbortTransaction(void)
 	s->parallelModeLevel = 0;
 	s->parallelChildXact = false;	/* should be false already */
 
+	/* Reset aclcheck tracking state */
+	aclcheck_tracking_active = false;
+
 	/*
 	 * do abort processing
 	 */
diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 007ede997c5..2a3f1ebac5f 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -44,6 +44,7 @@
 #include "access/sysattr.h"
 #include "access/tableam.h"
 #include "access/xact.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
@@ -81,9 +82,19 @@
 #include "utils/fmgroids.h"
 #include "utils/guc.h"
 #include "utils/lsyscache.h"
+#include "utils/memutils.h"
 #include "utils/rel.h"
 #include "utils/syscache.h"
 
+#define ACLCHECK_TRACK_INITIAL_SIZE 64
+
+static MemoryContext AclCheckTrackContext = NULL;
+
+AclCheckEntry *aclcheck_tracked = NULL;
+int			aclcheck_tracked_count = 0;
+int			aclcheck_tracked_max = 0;
+bool		aclcheck_tracking_active = false;
+
 /*
  * Internal format used by ALTER DEFAULT PRIVILEGES.
  */
@@ -3891,6 +3902,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4093,6 +4105,7 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5036,3 +5049,42 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Reset the tracking array. Called at each top-level ProcessUtility()
+ * to avoid carrying stale entries from a previous statement.
+ * Resets the memory context, freeing all prior allocations.
+ */
+void
+aclcheck_track_reset(void)
+{
+	if (AclCheckTrackContext == NULL)
+	{
+		AclCheckTrackContext = AllocSetContextCreate(TopMemoryContext,
+													 "AclCheckTrackContext",
+													 ALLOCSET_DEFAULT_SIZES);
+	}
+	else
+	{
+		MemoryContextReset(AclCheckTrackContext);
+	}
+
+	aclcheck_tracked = (AclCheckEntry *)
+		MemoryContextAlloc(AclCheckTrackContext,
+						   ACLCHECK_TRACK_INITIAL_SIZE * sizeof(AclCheckEntry));
+	aclcheck_tracked_max = ACLCHECK_TRACK_INITIAL_SIZE;
+	aclcheck_tracked_count = 0;
+	aclcheck_tracking_active = true;
+}
+
+/*
+ * Grow the tracking array when full. Doubles the size each time.
+ */
+void
+aclcheck_track_grow(void)
+{
+	aclcheck_tracked_max *= 2;
+	aclcheck_tracked = (AclCheckEntry *)
+		repalloc(aclcheck_tracked,
+				 aclcheck_tracked_max * sizeof(AclCheckEntry));
+}
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 9a7a401aced..8a4c2c9bb02 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -17,6 +17,7 @@
 #include "access/genam.h"
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
@@ -29,6 +30,8 @@
 #include "miscadmin.h"
 #include "storage/lmgr.h"
 #include "storage/lock.h"
+#include "storage/sinval.h"
+#include "utils/acl.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -38,6 +41,7 @@
 
 static bool isObjectPinned(const ObjectAddress *object);
 static void dependencyLockAndCheckObject(Oid classId, Oid objectId);
+static void recheckAcl(Oid classId, Oid objectId);
 
 
 /*
@@ -732,21 +736,74 @@ isObjectPinned(const ObjectAddress *object)
 }
 
 
+/*
+ * recheckAcl()
+ *
+ * Re-verify all tracked permission checks on the given object.
+ *
+ * Called after acquiring the lock and verifying the object still exists.
+ * If permission checks were tracked for this object and catalog
+ * invalidations arrived since the original checks, re-verify them all.
+ * This closes the TOCTOU window where a REVOKE could land between the
+ * original permission check and the dependency recording.
+ *
+ * Multiple checks may have been done on the same object with different
+ * modes or roles, so we iterate through all matching entries.
+ *
+ * Since we don't re-resolve names (the OID is fixed), there is no need for
+ * a retry loop here. If a recheck fails, it's a definitive failure.
+ *
+ * The linear scan over the tracking array is O(n) in the number of tracked
+ * entries, but that's fine since a typical DDL statement tracks only a few
+ * objects.
+ */
+static void
+recheckAcl(Oid classId, Oid objectId)
+{
+	for (int i = aclcheck_tracked_count - 1; i >= 0; i--)
+	{
+		if (aclcheck_tracked[i].classId == classId &&
+			aclcheck_tracked[i].objectId == objectId &&
+			aclcheck_tracked[i].inval_count != SharedInvalidMessageCounter)
+		{
+			AclResult	aclresult;
+
+			if (classId == RelationRelationId)
+				aclresult = pg_class_aclcheck(objectId,
+											  aclcheck_tracked[i].roleId,
+											  aclcheck_tracked[i].mode);
+			else
+				aclresult = object_aclcheck(classId, objectId,
+											aclcheck_tracked[i].roleId,
+											aclcheck_tracked[i].mode);
+
+			if (aclresult != ACLCHECK_OK)
+			{
+				ObjectAddress object;
+
+				object.classId = classId;
+				object.objectId = objectId;
+				object.objectSubId = 0;
+				ereport(ERROR,
+						(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
+						 errmsg("permission denied for %s",
+								getObjectDescription(&object, false))));
+			}
+		}
+	}
+}
+
+
 /*
  * dependencyLockAndCheckObject
  *
- * Lock the object that we are about to record a dependency on.  After it's
- * locked, verify that it hasn't been dropped while we weren't looking.  If it
- * has been dropped, throw an an error.
+ * Lock the object that we are about to record a dependency on. After it's
+ * locked, verify that it hasn't been dropped while we weren't looking. If it
+ * has been dropped, throw an error. Then re-verify any tracked permission
+ * check to close the TOCTOU window.
  *
  * If the caller already holds a lock that conflicts with DROP
- * (AccessShareLock or stronger), this does nothing.  Callers should acquire
- * locks already when they look up the referenced objects, but many callers
- * currently do not.  This is a backstop to make sure that we don't record a
- * bogus reference permanently in the catalogs in that case.  In the future,
- * after we have tightened up all the callers to acquire locks earlier, this
- * could just verify that the object is already locked and throw an error if
- * not.
+ * (AccessShareLock or stronger), this skips lock acquisition entirely.
  */
 static void
 dependencyLockAndCheckObject(Oid classId, Oid objectId)
@@ -773,20 +830,25 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 						   0);
 
 		if (LockHeldByMe(&tag, AccessShareLock, true))
+		{
+			/* Recheck ACL */
+			recheckAcl(classId, objectId);
 			return;
+		}
 
-		/* Assume we should lock the whole object not a sub-object */
+		/* Acquire lock */
 		LockDatabaseObject(classId, objectId, 0, AccessShareLock);
 
-		/*
-		 * Check that the object still exists.  If the catalog has a suitable
-		 * syscache, check that first.
-		 */
+		/* Check that the object still exists */
 		cache = get_object_catcache_oid(classId);
 		if (cache != SYSCACHEID_INVALID)
 		{
 			if (SearchSysCacheExists1(cache, ObjectIdGetDatum(objectId)))
+			{
+				/* Recheck ACL */
+				recheckAcl(classId, objectId);
 				return;
+			}
 		}
 
 		/*
@@ -814,6 +876,9 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 
 		systable_endscan(scan);
 		table_close(rel, AccessShareLock);
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 	else
 	{
@@ -834,14 +899,22 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		Assert(!IsSharedRelation(objectId));
 
 		if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
+		{
+			recheckAcl(classId, objectId);
 			return;
+		}
+
+		/* Acquire lock */
 		LockRelationOid(objectId, AccessShareLock);
 
-		if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
-			return;
-		ereport(ERROR,
-				(errcode(ERRCODE_UNDEFINED_OBJECT),
-				 errmsg("referenced relation was concurrently dropped")));
+		/* Check that the object still exists */
+		if (!SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
+			ereport(ERROR,
+					(errcode(ERRCODE_UNDEFINED_OBJECT),
+					 errmsg("referenced relation was concurrently dropped")));
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 }
 
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..cc72c616657 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -20,6 +20,7 @@
 #include "access/twophase.h"
 #include "access/xact.h"
 #include "access/xlog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
@@ -515,6 +516,13 @@ ProcessUtility(PlannedStmt *pstmt,
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
+	/*
+	 * Reset the aclcheck tracking for each top-level utility statement and
+	 * enable tracking for the duration of the statement.
+	 */
+	if (context == PROCESS_UTILITY_TOPLEVEL)
+		aclcheck_track_reset();
+
 	/*
 	 * We provide a function hook variable that lets loadable plugins get
 	 * control when ProcessUtility is called.  Such a plugin would normally
@@ -528,6 +536,9 @@ ProcessUtility(PlannedStmt *pstmt,
 		standard_ProcessUtility(pstmt, queryString, readOnlyTree,
 								context, params, queryEnv,
 								dest, qc);
+
+	if (context == PROCESS_UTILITY_TOPLEVEL)
+		aclcheck_tracking_active = false;
 }
 
 /*
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..0df90ccf42d
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,69 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Track permission checks for revalidation after lock acquisition
+ *	  in dependencyLockAndCheckObject().
+ *
+ * DDL may perform ACL checks on referenced objects without first holding a lock
+ * on them. In that case, the lock is acquired much later, when recording
+ * dependencies.
+ * Track the ACL checks, so that we can re-check them after acquiring the
+ * lock while recording dependencies.
+ *
+ * XXX: consider refactoring so that we perform the name lookup, acquire the
+ * lock, and check ACLs all in unison, like RangeVarGetRelidExtended().
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#include "storage/sinval.h"
+#include "utils/acl.h"
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+	Oid			roleId;
+	AclMode		mode;
+	uint64		inval_count;
+} AclCheckEntry;
+
+extern AclCheckEntry *aclcheck_tracked;
+extern int	aclcheck_tracked_count;
+extern int	aclcheck_tracked_max;
+extern bool aclcheck_tracking_active;
+
+extern void aclcheck_track_reset(void);
+extern void aclcheck_track_grow(void);
+
+/*
+ * Record an aclcheck for later revalidation.
+ *
+ * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Only records when inside an utility statement.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+{
+	if (!aclcheck_tracking_active)
+		return;
+
+	if (aclcheck_tracked_count >= aclcheck_tracked_max)
+		aclcheck_track_grow();
+
+	aclcheck_tracked[aclcheck_tracked_count].classId = classId;
+	aclcheck_tracked[aclcheck_tracked_count].objectId = objectId;
+	aclcheck_tracked[aclcheck_tracked_count].roleId = roleId;
+	aclcheck_tracked[aclcheck_tracked_count].mode = mode;
+	aclcheck_tracked[aclcheck_tracked_count].inval_count = SharedInvalidMessageCounter;
+	aclcheck_tracked_count++;
+}
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/test/isolation/expected/ddl-dependency-locking.out b/src/test/isolation/expected/ddl-dependency-locking.out
index 636de281022..002d537efb7 100644
--- a/src/test/isolation/expected/ddl-dependency-locking.out
+++ b/src/test/isolation/expected/ddl-dependency-locking.out
@@ -1,4 +1,4 @@
-Parsed test spec with 2 sessions
+Parsed test spec with 3 sessions
 
 starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
 step s1_begin: BEGIN;
@@ -135,3 +135,12 @@ step s2_drop_role: DROP ROLE regress_dependency; <waiting ...>
 step s1_commit: COMMIT;
 step s2_drop_role: <... completed>
 ERROR:  role "regress_dependency" cannot be dropped because some objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_as_role_user s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_as_role_user: SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_as_role_user: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_wrapper
diff --git a/src/test/isolation/specs/ddl-dependency-locking.spec b/src/test/isolation/specs/ddl-dependency-locking.spec
index de5bd88d35e..69e6fedf9f5 100644
--- a/src/test/isolation/specs/ddl-dependency-locking.spec
+++ b/src/test/isolation/specs/ddl-dependency-locking.spec
@@ -11,6 +11,10 @@ setup
 	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+	CREATE ROLE role_fdw;
+	CREATE ROLE role_user LOGIN;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_wrapper TO role_fdw;
+	GRANT role_fdw TO role_user;
 	CREATE ROLE regress_dependency;
 }
 
@@ -24,6 +28,7 @@ teardown
 	DROP FUNCTION IF EXISTS alterschema.falter();
 	DROP DOMAIN IF EXISTS idid;
 	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP SERVER IF EXISTS srv_role_revoked;
 	DROP TABLE IF EXISTS tabtype;
 	DROP SCHEMA IF EXISTS testschema;
 	DROP SCHEMA IF EXISTS alterschema;
@@ -32,6 +37,8 @@ teardown
 	DROP DOMAIN IF EXISTS id;
 	DROP FUNCTION IF EXISTS f();
 	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+	DROP ROLE IF EXISTS role_user;
+	DROP ROLE IF EXISTS role_fdw;
 	DROP ROLE regress_dependency;
 }
 
@@ -47,6 +54,7 @@ step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alte
 step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
 step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
 step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_create_server_as_role_user" { SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; }
 step "s1_commit" { COMMIT; }
 
 session "s2"
@@ -62,6 +70,11 @@ step "s2_drop_domain_id" { DROP DOMAIN id; }
 step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
 step "s2_drop_role" { DROP ROLE regress_dependency; }
 step "s2_commit" { COMMIT; }
+step "s2_rollback" { ROLLBACK; }
+
+session "s3"
+
+step "s3_revoke_role" { REVOKE role_fdw FROM role_user; }
 
 # create function - drop schema
 permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
@@ -102,3 +115,6 @@ permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
 # <OID> was concurrently dropped", contains an OID that is not stable.
 #
 # permutation "s2_begin" "s2_drop_role" "s1_alter_function_owner" "s2_commit"
+
+# Role membership TOCTOU: permission via role revoked during lock wait.
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_as_role_user" "s3_revoke_role" "s2_rollback"
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index 8cf40c87043..cb0cc25bda8 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -19,6 +19,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-09 18:04                                                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-09 18:04 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Tue, Jun 09, 2026 at 06:47:06AM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Mon, Jun 08, 2026 at 02:55:19PM -0700, Jeff Davis wrote:
> > On Fri, 2026-06-05 at 13:09 +0000, Bertrand Drouvot wrote:
> > > the current patch
> > 
> >   /*
> >    * Look up a tracked aclcheck entry for the given object.
> >    * Returns true if found, filling in roleId, mode, and inval_count.
> >    * Searches from the end to find the most recent check (the one with
> > the
> >    * freshest inval_count).
> > 
> > What if two tracked ACL checks had different modes? Don't you need to
> > do both checks or somehow combine the modes in the tracking entry?
> > 
> > (I'm not sure if this is a practical problem or not.)
> 
> Humm, good point. I was focusing on a "full" role revoke but maybe what you
> describe could be a practical problem (in case of privilege revoke from the
> role).
> 
> In order to be on the safe side of things, the attached now iterates through all
> matching entries (and not only the last one). It's still a flat array as its
> linear scan is O(n) in the number of tracked entries, but that's fine since a
> typical DDL statement tracks only a few objects.

I just realized that the cfbot is complaining, let me fix it and come back with
an updated patch.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-09 21:44                                                                                   ` Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2026-06-09 21:44 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Tue, 2026-06-09 at 06:47 +0000, Bertrand Drouvot wrote:
> In order to be on the safe side of things, the attached now iterates
> through all
> matching entries (and not only the last one).

I don't think:

  if (context == PROCESS_UTILITY_TOPLEVEL)

is quite right. With SPI, I bet you can end up in a situation where the
branch fires twice (causing an early reset) or not at all (because the
only call is PROCESS_UTLITY_QUERY).

In any case, I don't think mixing the tracking entries between entirely
different DDL commands is a good idea. If you execute DDL inside of SPI
in its own subtransaction, and it inserts a tracking entry to recheck
something, and then you roll back the subxact, you don't want the
tracking entry to then cause the outer transaction to fail. I didn't
test this, so if there's something preventing this kind of problem, let
me know.

We probably need to track where we are in the stack of ProcessUtility()
calls and keep the tracking entries separate, and always remove entries
from that level on return (or rollback).

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-10 12:31                                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-10 12:31 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Tue, Jun 09, 2026 at 02:44:10PM -0700, Jeff Davis wrote:
> Hi,
> 
> On Tue, 2026-06-09 at 06:47 +0000, Bertrand Drouvot wrote:
> > In order to be on the safe side of things, the attached now iterates
> > through all
> > matching entries (and not only the last one).
> 
> I don't think:
> 
>   if (context == PROCESS_UTILITY_TOPLEVEL)
> 
> is quite right.
> 
> In any case, I don't think mixing the tracking entries between entirely
> different DDL commands is a good idea. If you execute DDL inside of SPI
> in its own subtransaction, and it inserts a tracking entry to recheck
> something, and then you roll back the subxact, you don't want the
> tracking entry to then cause the outer transaction to fail. I didn't
> test this, so if there's something preventing this kind of problem, let
> me know.
> 
> We probably need to track where we are in the stack of ProcessUtility()
> calls and keep the tracking entries separate, and always remove entries
> from that level on return (or rollback).

I think you are right. I changed this in the attached so that aclcheck_tracked_count
is saved on entry and restored on return of each ProcessUtility call, so that each
nesting level's entries are kept separate.

Also, the reset is now done whenever tracking is initialized (means at the
outermost ProcessUtility call that starts tracking).

I think that addresses your concerns and it also fixes the issues reported
by the cfbot (that I mentioned up-thread).

I also added more tests related to nested calls.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v26-0001-Recheck-permissions-after-lock-acquisition-in-de.patch (28.6K, ../../ailZCCmS0bGlNBfe@bdtpg/2-v26-0001-Recheck-permissions-after-lock-acquisition-in-de.patch)
  download | inline diff:
From 49222c5632152a5896db45e0b836baaa38ef9d04 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Sat, 30 May 2026 14:35:40 +0000
Subject: [PATCH v26] Recheck permissions after lock acquisition in dependency
 recording

After dependencyLockAndCheckObject() acquires a lock on a referenced object
(which may have blocked on a concurrent DROP), re-verify any permission check
that was done earlier in the statement. This closes the TOCTOU window where a
REVOKE could land between the original permission check and the dependency
recording.

The approach: record SharedInvalidMessageCounter at the time of the original
aclcheck. After acquiring the lock and verifying the object still exists,
compare the saved counter with the current value. If it changed (meaning
catalog invalidations arrived since the original check), re-verify the
permission. Since the OID is fixed (no name re-resolution), a failure is
definitive and no retry loop is needed.

The tracking array lives in a dedicated AclCheckTrackContext memory context
(child of TopMemoryContext). The context is reset whenever tracking is
initialized (at the outermost ProcessUtility call that starts tracking), which
frees all prior allocations and provides clean lifetime management.

Recording is gated by aclcheck_tracking_active, which is set to true at the first
ProcessUtility call and cleared on its return or in AbortTransaction. This
ensures DML and queries pay no cost.

aclcheck_tracked_count is saved on entry and restored on return of each
ProcessUtility call, so that each nesting level's entries are kept separate.
This prevents nested calls from polluting the outer level's tracked entries and
ensures the outer DDL's recheck still finds its own tracked entries after a
nested call returns.

Alternatives considered:

- To avoid allocating memory for each statement, keep the array in
TopMemoryContext and never free it (only resetting the count). But that left the
high-water mark allocated for the lifetime of the backend.

- Passing privilege info (roleId, mode) as extra arguments through the
  dependency recording APIs (recordDependencyOn, recordMultipleDependencies,
  etc.) was discarded because expression-based dependencies
  (recordDependencyOnExpr, find_expr_references_walker) discover objects by
  walking expression trees: the caller never sees individual objects and cannot
  attach privilege info to them.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/access/transam/xact.c             |   4 +
 src/backend/catalog/aclchk.c                  |  52 ++++++++
 src/backend/catalog/pg_depend.c               | 113 ++++++++++++++----
 src/backend/tcop/utility.c                    |  28 +++++
 src/include/catalog/aclcheck_track.h          |  69 +++++++++++
 .../expected/ddl-dependency-locking.out       |  56 ++++++++-
 .../specs/ddl-dependency-locking.spec         | 109 +++++++++++++++++
 src/tools/pgindent/typedefs.list              |   1 +
 8 files changed, 411 insertions(+), 21 deletions(-)
  29.3% src/backend/catalog/
   4.1% src/backend/tcop/
  12.4% src/include/catalog/
  18.9% src/test/isolation/expected/
  34.3% src/test/isolation/specs/

diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c
index 5586fbe5b07..1a6088bf2f7 100644
--- a/src/backend/access/transam/xact.c
+++ b/src/backend/access/transam/xact.c
@@ -32,6 +32,7 @@
 #include "access/xlogrecovery.h"
 #include "access/xlogutils.h"
 #include "access/xlogwait.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/index.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_enum.h"
@@ -2961,6 +2962,9 @@ AbortTransaction(void)
 	s->parallelModeLevel = 0;
 	s->parallelChildXact = false;	/* should be false already */
 
+	/* Reset aclcheck tracking state */
+	aclcheck_tracking_active = false;
+
 	/*
 	 * do abort processing
 	 */
diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 007ede997c5..2a3f1ebac5f 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -44,6 +44,7 @@
 #include "access/sysattr.h"
 #include "access/tableam.h"
 #include "access/xact.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
@@ -81,9 +82,19 @@
 #include "utils/fmgroids.h"
 #include "utils/guc.h"
 #include "utils/lsyscache.h"
+#include "utils/memutils.h"
 #include "utils/rel.h"
 #include "utils/syscache.h"
 
+#define ACLCHECK_TRACK_INITIAL_SIZE 64
+
+static MemoryContext AclCheckTrackContext = NULL;
+
+AclCheckEntry *aclcheck_tracked = NULL;
+int			aclcheck_tracked_count = 0;
+int			aclcheck_tracked_max = 0;
+bool		aclcheck_tracking_active = false;
+
 /*
  * Internal format used by ALTER DEFAULT PRIVILEGES.
  */
@@ -3891,6 +3902,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4093,6 +4105,7 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5036,3 +5049,42 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Reset the tracking array. Called at each top-level ProcessUtility()
+ * to avoid carrying stale entries from a previous statement.
+ * Resets the memory context, freeing all prior allocations.
+ */
+void
+aclcheck_track_reset(void)
+{
+	if (AclCheckTrackContext == NULL)
+	{
+		AclCheckTrackContext = AllocSetContextCreate(TopMemoryContext,
+													 "AclCheckTrackContext",
+													 ALLOCSET_DEFAULT_SIZES);
+	}
+	else
+	{
+		MemoryContextReset(AclCheckTrackContext);
+	}
+
+	aclcheck_tracked = (AclCheckEntry *)
+		MemoryContextAlloc(AclCheckTrackContext,
+						   ACLCHECK_TRACK_INITIAL_SIZE * sizeof(AclCheckEntry));
+	aclcheck_tracked_max = ACLCHECK_TRACK_INITIAL_SIZE;
+	aclcheck_tracked_count = 0;
+	aclcheck_tracking_active = true;
+}
+
+/*
+ * Grow the tracking array when full. Doubles the size each time.
+ */
+void
+aclcheck_track_grow(void)
+{
+	aclcheck_tracked_max *= 2;
+	aclcheck_tracked = (AclCheckEntry *)
+		repalloc(aclcheck_tracked,
+				 aclcheck_tracked_max * sizeof(AclCheckEntry));
+}
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 9a7a401aced..8a4c2c9bb02 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -17,6 +17,7 @@
 #include "access/genam.h"
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
@@ -29,6 +30,8 @@
 #include "miscadmin.h"
 #include "storage/lmgr.h"
 #include "storage/lock.h"
+#include "storage/sinval.h"
+#include "utils/acl.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -38,6 +41,7 @@
 
 static bool isObjectPinned(const ObjectAddress *object);
 static void dependencyLockAndCheckObject(Oid classId, Oid objectId);
+static void recheckAcl(Oid classId, Oid objectId);
 
 
 /*
@@ -732,21 +736,74 @@ isObjectPinned(const ObjectAddress *object)
 }
 
 
+/*
+ * recheckAcl()
+ *
+ * Re-verify all tracked permission checks on the given object.
+ *
+ * Called after acquiring the lock and verifying the object still exists.
+ * If permission checks were tracked for this object and catalog
+ * invalidations arrived since the original checks, re-verify them all.
+ * This closes the TOCTOU window where a REVOKE could land between the
+ * original permission check and the dependency recording.
+ *
+ * Multiple checks may have been done on the same object with different
+ * modes or roles, so we iterate through all matching entries.
+ *
+ * Since we don't re-resolve names (the OID is fixed), there is no need for
+ * a retry loop here. If a recheck fails, it's a definitive failure.
+ *
+ * The linear scan over the tracking array is O(n) in the number of tracked
+ * entries, but that's fine since a typical DDL statement tracks only a few
+ * objects.
+ */
+static void
+recheckAcl(Oid classId, Oid objectId)
+{
+	for (int i = aclcheck_tracked_count - 1; i >= 0; i--)
+	{
+		if (aclcheck_tracked[i].classId == classId &&
+			aclcheck_tracked[i].objectId == objectId &&
+			aclcheck_tracked[i].inval_count != SharedInvalidMessageCounter)
+		{
+			AclResult	aclresult;
+
+			if (classId == RelationRelationId)
+				aclresult = pg_class_aclcheck(objectId,
+											  aclcheck_tracked[i].roleId,
+											  aclcheck_tracked[i].mode);
+			else
+				aclresult = object_aclcheck(classId, objectId,
+											aclcheck_tracked[i].roleId,
+											aclcheck_tracked[i].mode);
+
+			if (aclresult != ACLCHECK_OK)
+			{
+				ObjectAddress object;
+
+				object.classId = classId;
+				object.objectId = objectId;
+				object.objectSubId = 0;
+				ereport(ERROR,
+						(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
+						 errmsg("permission denied for %s",
+								getObjectDescription(&object, false))));
+			}
+		}
+	}
+}
+
+
 /*
  * dependencyLockAndCheckObject
  *
- * Lock the object that we are about to record a dependency on.  After it's
- * locked, verify that it hasn't been dropped while we weren't looking.  If it
- * has been dropped, throw an an error.
+ * Lock the object that we are about to record a dependency on. After it's
+ * locked, verify that it hasn't been dropped while we weren't looking. If it
+ * has been dropped, throw an error. Then re-verify any tracked permission
+ * check to close the TOCTOU window.
  *
  * If the caller already holds a lock that conflicts with DROP
- * (AccessShareLock or stronger), this does nothing.  Callers should acquire
- * locks already when they look up the referenced objects, but many callers
- * currently do not.  This is a backstop to make sure that we don't record a
- * bogus reference permanently in the catalogs in that case.  In the future,
- * after we have tightened up all the callers to acquire locks earlier, this
- * could just verify that the object is already locked and throw an error if
- * not.
+ * (AccessShareLock or stronger), this skips lock acquisition entirely.
  */
 static void
 dependencyLockAndCheckObject(Oid classId, Oid objectId)
@@ -773,20 +830,25 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 						   0);
 
 		if (LockHeldByMe(&tag, AccessShareLock, true))
+		{
+			/* Recheck ACL */
+			recheckAcl(classId, objectId);
 			return;
+		}
 
-		/* Assume we should lock the whole object not a sub-object */
+		/* Acquire lock */
 		LockDatabaseObject(classId, objectId, 0, AccessShareLock);
 
-		/*
-		 * Check that the object still exists.  If the catalog has a suitable
-		 * syscache, check that first.
-		 */
+		/* Check that the object still exists */
 		cache = get_object_catcache_oid(classId);
 		if (cache != SYSCACHEID_INVALID)
 		{
 			if (SearchSysCacheExists1(cache, ObjectIdGetDatum(objectId)))
+			{
+				/* Recheck ACL */
+				recheckAcl(classId, objectId);
 				return;
+			}
 		}
 
 		/*
@@ -814,6 +876,9 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 
 		systable_endscan(scan);
 		table_close(rel, AccessShareLock);
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 	else
 	{
@@ -834,14 +899,22 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		Assert(!IsSharedRelation(objectId));
 
 		if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
+		{
+			recheckAcl(classId, objectId);
 			return;
+		}
+
+		/* Acquire lock */
 		LockRelationOid(objectId, AccessShareLock);
 
-		if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
-			return;
-		ereport(ERROR,
-				(errcode(ERRCODE_UNDEFINED_OBJECT),
-				 errmsg("referenced relation was concurrently dropped")));
+		/* Check that the object still exists */
+		if (!SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
+			ereport(ERROR,
+					(errcode(ERRCODE_UNDEFINED_OBJECT),
+					 errmsg("referenced relation was concurrently dropped")));
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 }
 
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..0d0f48715b5 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -20,6 +20,7 @@
 #include "access/twophase.h"
 #include "access/xact.h"
 #include "access/xlog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
@@ -510,11 +511,29 @@ ProcessUtility(PlannedStmt *pstmt,
 			   DestReceiver *dest,
 			   QueryCompletion *qc)
 {
+	int			save_aclcheck_count;
+	bool		was_tracking = aclcheck_tracking_active;
+
 	Assert(IsA(pstmt, PlannedStmt));
 	Assert(pstmt->commandType == CMD_UTILITY);
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
+	/*
+	 * Set up aclcheck tracking. For the top-level call, we initialize. For
+	 * nested calls, we save the current position so we can discard entries
+	 * from this level on return preserving the outer level's entries.
+	 */
+	if (!was_tracking)
+	{
+		aclcheck_track_reset();
+		save_aclcheck_count = 0;
+	}
+	else
+	{
+		save_aclcheck_count = aclcheck_tracked_count;
+	}
+
 	/*
 	 * We provide a function hook variable that lets loadable plugins get
 	 * control when ProcessUtility is called.  Such a plugin would normally
@@ -528,6 +547,15 @@ ProcessUtility(PlannedStmt *pstmt,
 		standard_ProcessUtility(pstmt, queryString, readOnlyTree,
 								context, params, queryEnv,
 								dest, qc);
+
+	/*
+	 * Restore the tracked entry count, discarding entries added at this
+	 * nesting level while preserving outer levels' entries.
+	 */
+	aclcheck_tracked_count = save_aclcheck_count;
+
+	if (!was_tracking)
+		aclcheck_tracking_active = false;
 }
 
 /*
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..0df90ccf42d
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,69 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Track permission checks for revalidation after lock acquisition
+ *	  in dependencyLockAndCheckObject().
+ *
+ * DDL may perform ACL checks on referenced objects without first holding a lock
+ * on them. In that case, the lock is acquired much later, when recording
+ * dependencies.
+ * Track the ACL checks, so that we can re-check them after acquiring the
+ * lock while recording dependencies.
+ *
+ * XXX: consider refactoring so that we perform the name lookup, acquire the
+ * lock, and check ACLs all in unison, like RangeVarGetRelidExtended().
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#include "storage/sinval.h"
+#include "utils/acl.h"
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+	Oid			roleId;
+	AclMode		mode;
+	uint64		inval_count;
+} AclCheckEntry;
+
+extern AclCheckEntry *aclcheck_tracked;
+extern int	aclcheck_tracked_count;
+extern int	aclcheck_tracked_max;
+extern bool aclcheck_tracking_active;
+
+extern void aclcheck_track_reset(void);
+extern void aclcheck_track_grow(void);
+
+/*
+ * Record an aclcheck for later revalidation.
+ *
+ * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Only records when inside an utility statement.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+{
+	if (!aclcheck_tracking_active)
+		return;
+
+	if (aclcheck_tracked_count >= aclcheck_tracked_max)
+		aclcheck_track_grow();
+
+	aclcheck_tracked[aclcheck_tracked_count].classId = classId;
+	aclcheck_tracked[aclcheck_tracked_count].objectId = objectId;
+	aclcheck_tracked[aclcheck_tracked_count].roleId = roleId;
+	aclcheck_tracked[aclcheck_tracked_count].mode = mode;
+	aclcheck_tracked[aclcheck_tracked_count].inval_count = SharedInvalidMessageCounter;
+	aclcheck_tracked_count++;
+}
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/test/isolation/expected/ddl-dependency-locking.out b/src/test/isolation/expected/ddl-dependency-locking.out
index 636de281022..0544efe9d76 100644
--- a/src/test/isolation/expected/ddl-dependency-locking.out
+++ b/src/test/isolation/expected/ddl-dependency-locking.out
@@ -1,4 +1,4 @@
-Parsed test spec with 2 sessions
+Parsed test spec with 3 sessions
 
 starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
 step s1_begin: BEGIN;
@@ -135,3 +135,57 @@ step s2_drop_role: DROP ROLE regress_dependency; <waiting ...>
 step s1_commit: COMMIT;
 step s2_drop_role: <... completed>
 ERROR:  role "regress_dependency" cannot be dropped because some objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_as_role_user s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_as_role_user: SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_as_role_user: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_wrapper
+
+starting permutation: s2_begin s2_drop_fdw_spi_func s1_create_server_spi_func s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_spi_func: DROP FOREIGN DATA WRAPPER fdw_spi_func RESTRICT;
+step s1_create_server_spi_func: SET ROLE role_user; CREATE SERVER srv_spi_func FOREIGN DATA WRAPPER fdw_spi_func; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_spi_func: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_spi_func
+
+starting permutation: s2_begin s2_drop_fdw_spi_rollback s1_create_server_spi_rollback s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_spi_rollback: DROP FOREIGN DATA WRAPPER fdw_spi_rollback RESTRICT;
+step s1_create_server_spi_rollback: SET ROLE role_user; CREATE SERVER srv_spi_rollback FOREIGN DATA WRAPPER fdw_spi_rollback; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_spi_rollback: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_spi_rollback
+
+starting permutation: s2_begin s2_drop_fdw_trigger s1_insert_trigger_ddl s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_trigger: DROP FOREIGN DATA WRAPPER fdw_trigger RESTRICT;
+step s1_insert_trigger_ddl: SET ROLE role_user; INSERT INTO trigger_tbl VALUES (1); RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_insert_trigger_ddl: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_trigger
+
+starting permutation: s2_begin s2_drop_fdw_trigger_spi s1_insert_trigger_spi_ddl s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_trigger_spi: DROP FOREIGN DATA WRAPPER fdw_trigger_spi_func RESTRICT;
+step s1_insert_trigger_spi_ddl: SET ROLE role_user; INSERT INTO trigger_spi_tbl VALUES (1); RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_insert_trigger_spi_ddl: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_trigger_spi_func
+
+starting permutation: s2_begin s2_drop_fdw_inner s1_create_server_nested_toctou s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_inner: DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT;
+step s1_create_server_nested_toctou: SET ROLE role_user; CREATE SERVER srv_outer FOREIGN DATA WRAPPER fdw_outer; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_nested_toctou: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_inner
diff --git a/src/test/isolation/specs/ddl-dependency-locking.spec b/src/test/isolation/specs/ddl-dependency-locking.spec
index de5bd88d35e..5a08a8ffabe 100644
--- a/src/test/isolation/specs/ddl-dependency-locking.spec
+++ b/src/test/isolation/specs/ddl-dependency-locking.spec
@@ -11,7 +11,54 @@ setup
 	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+	CREATE ROLE role_fdw;
+	CREATE ROLE role_user LOGIN;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_wrapper TO role_fdw;
+	GRANT role_fdw TO role_user;
 	CREATE ROLE regress_dependency;
+	CREATE FUNCTION spi_func(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE TEMP TABLE IF NOT EXISTS validator_side_effect(x int)'; END; $$;
+	CREATE FUNCTION spi_func_rollback(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    BEGIN
+	      EXECUTE 'CREATE TEMP TABLE validator_will_rollback(x int)';
+	      RAISE EXCEPTION 'force rollback';
+	    EXCEPTION WHEN OTHERS THEN
+	      NULL;
+	    END;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_spi_func VALIDATOR spi_func;
+	CREATE FOREIGN DATA WRAPPER fdw_spi_rollback VALIDATOR spi_func_rollback;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_spi_func TO role_fdw;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_spi_rollback TO role_fdw;
+	CREATE FOREIGN DATA WRAPPER fdw_trigger;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_trigger TO role_fdw;
+	CREATE FUNCTION trg_create_server() RETURNS trigger
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE SERVER srv_from_trigger FOREIGN DATA WRAPPER fdw_trigger'; RETURN NEW; END; $$;
+	CREATE TABLE trigger_tbl(a int);
+	GRANT INSERT ON trigger_tbl TO role_user;
+	CREATE TRIGGER trg BEFORE INSERT ON trigger_tbl
+	  FOR EACH ROW EXECUTE FUNCTION trg_create_server();
+	CREATE FOREIGN DATA WRAPPER fdw_trigger_spi_func VALIDATOR spi_func;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_trigger_spi_func TO role_fdw;
+	CREATE FUNCTION trg_create_server_spi_func() RETURNS trigger
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE SERVER srv_from_trigger_spi FOREIGN DATA WRAPPER fdw_trigger_spi_func'; RETURN NEW; END; $$;
+	CREATE TABLE trigger_spi_tbl(a int);
+	GRANT INSERT ON trigger_spi_tbl TO role_user;
+	CREATE TRIGGER trg BEFORE INSERT ON trigger_spi_tbl
+	  FOR EACH ROW EXECUTE FUNCTION trg_create_server_spi_func();
+	CREATE FOREIGN DATA WRAPPER fdw_inner;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_inner TO role_fdw;
+	CREATE FUNCTION spi_func_create_server(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    IF $2 = 'pg_catalog.pg_foreign_server'::regclass::oid THEN
+	      EXECUTE 'CREATE SERVER srv_nested_inner FOREIGN DATA WRAPPER fdw_inner';
+	    END IF;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_outer VALIDATOR spi_func_create_server;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_outer TO role_fdw;
 }
 
 teardown
@@ -24,7 +71,17 @@ teardown
 	DROP FUNCTION IF EXISTS alterschema.falter();
 	DROP DOMAIN IF EXISTS idid;
 	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP SERVER IF EXISTS srv_role_revoked;
+	DROP SERVER IF EXISTS srv_spi_func;
+	DROP SERVER IF EXISTS srv_spi_rollback;
+	DROP SERVER IF EXISTS srv_from_trigger;
+	DROP SERVER IF EXISTS srv_from_trigger_spi;
+	DROP SERVER IF EXISTS srv_from_spi;
+	DROP SERVER IF EXISTS srv_nested_inner;
+	DROP SERVER IF EXISTS srv_outer;
 	DROP TABLE IF EXISTS tabtype;
+	DROP TABLE IF EXISTS trigger_tbl;
+	DROP TABLE IF EXISTS trigger_spi_tbl;
 	DROP SCHEMA IF EXISTS testschema;
 	DROP SCHEMA IF EXISTS alterschema;
 	DROP TYPE IF EXISTS public.foo;
@@ -32,6 +89,19 @@ teardown
 	DROP DOMAIN IF EXISTS id;
 	DROP FUNCTION IF EXISTS f();
 	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_spi_func;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_spi_rollback;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_trigger;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_trigger_spi_func;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_inner;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_outer;
+	DROP FUNCTION IF EXISTS spi_func(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_rollback(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_create_server(text[], oid);
+	DROP FUNCTION IF EXISTS trg_create_server();
+	DROP FUNCTION IF EXISTS trg_create_server_spi_func();
+	DROP ROLE IF EXISTS role_user;
+	DROP ROLE IF EXISTS role_fdw;
 	DROP ROLE regress_dependency;
 }
 
@@ -47,6 +117,12 @@ step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alte
 step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
 step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
 step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_create_server_as_role_user" { SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; }
+step "s1_create_server_spi_func" { SET ROLE role_user; CREATE SERVER srv_spi_func FOREIGN DATA WRAPPER fdw_spi_func; RESET ROLE; }
+step "s1_create_server_spi_rollback" { SET ROLE role_user; CREATE SERVER srv_spi_rollback FOREIGN DATA WRAPPER fdw_spi_rollback; RESET ROLE; }
+step "s1_insert_trigger_ddl" { SET ROLE role_user; INSERT INTO trigger_tbl VALUES (1); RESET ROLE; }
+step "s1_insert_trigger_spi_ddl" { SET ROLE role_user; INSERT INTO trigger_spi_tbl VALUES (1); RESET ROLE; }
+step "s1_create_server_nested_toctou" { SET ROLE role_user; CREATE SERVER srv_outer FOREIGN DATA WRAPPER fdw_outer; RESET ROLE; }
 step "s1_commit" { COMMIT; }
 
 session "s2"
@@ -60,8 +136,18 @@ step "s2_drop_footab_type" { DROP TYPE public.footab; }
 step "s2_drop_function_f" { DROP FUNCTION f(); }
 step "s2_drop_domain_id" { DROP DOMAIN id; }
 step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_drop_fdw_spi_func" { DROP FOREIGN DATA WRAPPER fdw_spi_func RESTRICT; }
+step "s2_drop_fdw_spi_rollback" { DROP FOREIGN DATA WRAPPER fdw_spi_rollback RESTRICT; }
+step "s2_drop_fdw_trigger" { DROP FOREIGN DATA WRAPPER fdw_trigger RESTRICT; }
+step "s2_drop_fdw_trigger_spi" { DROP FOREIGN DATA WRAPPER fdw_trigger_spi_func RESTRICT; }
+step "s2_drop_fdw_inner" { DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT; }
 step "s2_drop_role" { DROP ROLE regress_dependency; }
 step "s2_commit" { COMMIT; }
+step "s2_rollback" { ROLLBACK; }
+
+session "s3"
+
+step "s3_revoke_role" { REVOKE role_fdw FROM role_user; }
 
 # create function - drop schema
 permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
@@ -102,3 +188,26 @@ permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
 # <OID> was concurrently dropped", contains an OID that is not stable.
 #
 # permutation "s2_begin" "s2_drop_role" "s1_alter_function_owner" "s2_commit"
+
+# Role membership TOCTOU: permission via role revoked during lock wait.
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_as_role_user" "s3_revoke_role" "s2_rollback"
+
+# Role membership TOCTOU with SPI DDL in FDW validator.
+permutation "s2_begin" "s2_drop_fdw_spi_func" "s1_create_server_spi_func" "s3_revoke_role" "s2_rollback"
+
+# Same as above but the validator's SPI DDL fails and rolls back its
+# subtransaction.
+permutation "s2_begin" "s2_drop_fdw_spi_rollback" "s1_create_server_spi_rollback" "s3_revoke_role" "s2_rollback"
+
+# Role membership TOCTOU with DDL triggered from DML: a trigger function does
+# DDL via SPI during INSERT.
+permutation "s2_begin" "s2_drop_fdw_trigger" "s1_insert_trigger_ddl" "s3_revoke_role" "s2_rollback"
+
+# Same as above but the DDL inside the trigger uses an FDW with a SPI validator,
+# combining trigger-initiated DDL with nested SPI.
+permutation "s2_begin" "s2_drop_fdw_trigger_spi" "s1_insert_trigger_spi_ddl" "s3_revoke_role" "s2_rollback"
+
+# TOCTOU on the nested SPI DDL itself: the validator creates a server using
+# fdw_inner, session 2 blocks that by dropping fdw_inner, and the REVOKE
+# removes access to fdw_inner.
+permutation "s2_begin" "s2_drop_fdw_inner" "s1_create_server_nested_toctou" "s3_revoke_role" "s2_rollback"
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index 8cf40c87043..cb0cc25bda8 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -19,6 +19,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-10 15:16                                                                                       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-10 15:16 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Wed, Jun 10, 2026 at 12:31:04PM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Tue, Jun 09, 2026 at 02:44:10PM -0700, Jeff Davis wrote:
> > Hi,
> > 
> > On Tue, 2026-06-09 at 06:47 +0000, Bertrand Drouvot wrote:
> > > In order to be on the safe side of things, the attached now iterates
> > > through all
> > > matching entries (and not only the last one).
> > 
> > I don't think:
> > 
> >   if (context == PROCESS_UTILITY_TOPLEVEL)
> > 
> > is quite right.
> > 
> > In any case, I don't think mixing the tracking entries between entirely
> > different DDL commands is a good idea. If you execute DDL inside of SPI
> > in its own subtransaction, and it inserts a tracking entry to recheck
> > something, and then you roll back the subxact, you don't want the
> > tracking entry to then cause the outer transaction to fail. I didn't
> > test this, so if there's something preventing this kind of problem, let
> > me know.
> > 
> > We probably need to track where we are in the stack of ProcessUtility()
> > calls and keep the tracking entries separate, and always remove entries
> > from that level on return (or rollback).
> 
> I think you are right. I changed this in the attached so that aclcheck_tracked_count
> is saved on entry and restored on return of each ProcessUtility call, so that each
> nesting level's entries are kept separate.
> 
> Also, the reset is now done whenever tracking is initialized (means at the
> outermost ProcessUtility call that starts tracking).
> 
> I think that addresses your concerns and it also fixes the issues reported
> by the cfbot (that I mentioned up-thread).
> 
> I also added more tests related to nested calls.

PFA a new version of v26, it adds a new test as compared to the v26 previously
shared.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v26-0001-Recheck-permissions-after-lock-acquisition-in-de.patch (30.6K, ../../ail%2F6I6mcitovsUo@bdtpg/2-v26-0001-Recheck-permissions-after-lock-acquisition-in-de.patch)
  download | inline diff:
From 3e65299a205b00c81e6c34958b425be53564001f Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Sat, 30 May 2026 14:35:40 +0000
Subject: [PATCH v26] Recheck permissions after lock acquisition in dependency
 recording

After dependencyLockAndCheckObject() acquires a lock on a referenced object
(which may have blocked on a concurrent DROP), re-verify any permission check
that was done earlier in the statement. This closes the TOCTOU window where a
REVOKE could land between the original permission check and the dependency
recording.

The approach: record SharedInvalidMessageCounter at the time of the original
aclcheck. After acquiring the lock and verifying the object still exists,
compare the saved counter with the current value. If it changed (meaning
catalog invalidations arrived since the original check), re-verify the
permission. Since the OID is fixed (no name re-resolution), a failure is
definitive and no retry loop is needed.

The tracking array lives in a dedicated AclCheckTrackContext memory context
(child of TopMemoryContext). The context is reset whenever tracking is
initialized (at the outermost ProcessUtility call that starts tracking), which
frees all prior allocations and provides clean lifetime management.

Recording is gated by aclcheck_tracking_active, which is set to true at the first
ProcessUtility call and cleared on its return or in AbortTransaction. This
ensures DML and queries pay no cost.

aclcheck_tracked_count is saved on entry and restored on return of each
ProcessUtility call, so that each nesting level's entries are kept separate.
This prevents nested calls from polluting the outer level's tracked entries and
ensures the outer DDL's recheck still finds its own tracked entries after a
nested call returns.

Alternatives considered:

- To avoid allocating memory for each statement, keep the array in
TopMemoryContext and never free it (only resetting the count). But that left the
high-water mark allocated for the lifetime of the backend.

- Passing privilege info (roleId, mode) as extra arguments through the
  dependency recording APIs (recordDependencyOn, recordMultipleDependencies,
  etc.) was discarded because expression-based dependencies
  (recordDependencyOnExpr, find_expr_references_walker) discover objects by
  walking expression trees: the caller never sees individual objects and cannot
  attach privilege info to them.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/access/transam/xact.c             |   4 +
 src/backend/catalog/aclchk.c                  |  52 +++++++
 src/backend/catalog/pg_depend.c               | 113 +++++++++++---
 src/backend/tcop/utility.c                    |  28 ++++
 src/include/catalog/aclcheck_track.h          |  69 +++++++++
 .../expected/ddl-dependency-locking.out       |  64 +++++++-
 .../specs/ddl-dependency-locking.spec         | 140 ++++++++++++++++++
 src/tools/pgindent/typedefs.list              |   1 +
 8 files changed, 450 insertions(+), 21 deletions(-)
 create mode 100644 src/include/catalog/aclcheck_track.h

diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c
index 5586fbe5b07..1a6088bf2f7 100644
--- a/src/backend/access/transam/xact.c
+++ b/src/backend/access/transam/xact.c
@@ -32,6 +32,7 @@
 #include "access/xlogrecovery.h"
 #include "access/xlogutils.h"
 #include "access/xlogwait.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/index.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_enum.h"
@@ -2961,6 +2962,9 @@ AbortTransaction(void)
 	s->parallelModeLevel = 0;
 	s->parallelChildXact = false;	/* should be false already */
 
+	/* Reset aclcheck tracking state */
+	aclcheck_tracking_active = false;
+
 	/*
 	 * do abort processing
 	 */
diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 007ede997c5..2a3f1ebac5f 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -44,6 +44,7 @@
 #include "access/sysattr.h"
 #include "access/tableam.h"
 #include "access/xact.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
@@ -81,9 +82,19 @@
 #include "utils/fmgroids.h"
 #include "utils/guc.h"
 #include "utils/lsyscache.h"
+#include "utils/memutils.h"
 #include "utils/rel.h"
 #include "utils/syscache.h"
 
+#define ACLCHECK_TRACK_INITIAL_SIZE 64
+
+static MemoryContext AclCheckTrackContext = NULL;
+
+AclCheckEntry *aclcheck_tracked = NULL;
+int			aclcheck_tracked_count = 0;
+int			aclcheck_tracked_max = 0;
+bool		aclcheck_tracking_active = false;
+
 /*
  * Internal format used by ALTER DEFAULT PRIVILEGES.
  */
@@ -3891,6 +3902,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4093,6 +4105,7 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5036,3 +5049,42 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Reset the tracking array. Called at each top-level ProcessUtility()
+ * to avoid carrying stale entries from a previous statement.
+ * Resets the memory context, freeing all prior allocations.
+ */
+void
+aclcheck_track_reset(void)
+{
+	if (AclCheckTrackContext == NULL)
+	{
+		AclCheckTrackContext = AllocSetContextCreate(TopMemoryContext,
+													 "AclCheckTrackContext",
+													 ALLOCSET_DEFAULT_SIZES);
+	}
+	else
+	{
+		MemoryContextReset(AclCheckTrackContext);
+	}
+
+	aclcheck_tracked = (AclCheckEntry *)
+		MemoryContextAlloc(AclCheckTrackContext,
+						   ACLCHECK_TRACK_INITIAL_SIZE * sizeof(AclCheckEntry));
+	aclcheck_tracked_max = ACLCHECK_TRACK_INITIAL_SIZE;
+	aclcheck_tracked_count = 0;
+	aclcheck_tracking_active = true;
+}
+
+/*
+ * Grow the tracking array when full. Doubles the size each time.
+ */
+void
+aclcheck_track_grow(void)
+{
+	aclcheck_tracked_max *= 2;
+	aclcheck_tracked = (AclCheckEntry *)
+		repalloc(aclcheck_tracked,
+				 aclcheck_tracked_max * sizeof(AclCheckEntry));
+}
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 9a7a401aced..8a4c2c9bb02 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -17,6 +17,7 @@
 #include "access/genam.h"
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
@@ -29,6 +30,8 @@
 #include "miscadmin.h"
 #include "storage/lmgr.h"
 #include "storage/lock.h"
+#include "storage/sinval.h"
+#include "utils/acl.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -38,6 +41,7 @@
 
 static bool isObjectPinned(const ObjectAddress *object);
 static void dependencyLockAndCheckObject(Oid classId, Oid objectId);
+static void recheckAcl(Oid classId, Oid objectId);
 
 
 /*
@@ -732,21 +736,74 @@ isObjectPinned(const ObjectAddress *object)
 }
 
 
+/*
+ * recheckAcl()
+ *
+ * Re-verify all tracked permission checks on the given object.
+ *
+ * Called after acquiring the lock and verifying the object still exists.
+ * If permission checks were tracked for this object and catalog
+ * invalidations arrived since the original checks, re-verify them all.
+ * This closes the TOCTOU window where a REVOKE could land between the
+ * original permission check and the dependency recording.
+ *
+ * Multiple checks may have been done on the same object with different
+ * modes or roles, so we iterate through all matching entries.
+ *
+ * Since we don't re-resolve names (the OID is fixed), there is no need for
+ * a retry loop here. If a recheck fails, it's a definitive failure.
+ *
+ * The linear scan over the tracking array is O(n) in the number of tracked
+ * entries, but that's fine since a typical DDL statement tracks only a few
+ * objects.
+ */
+static void
+recheckAcl(Oid classId, Oid objectId)
+{
+	for (int i = aclcheck_tracked_count - 1; i >= 0; i--)
+	{
+		if (aclcheck_tracked[i].classId == classId &&
+			aclcheck_tracked[i].objectId == objectId &&
+			aclcheck_tracked[i].inval_count != SharedInvalidMessageCounter)
+		{
+			AclResult	aclresult;
+
+			if (classId == RelationRelationId)
+				aclresult = pg_class_aclcheck(objectId,
+											  aclcheck_tracked[i].roleId,
+											  aclcheck_tracked[i].mode);
+			else
+				aclresult = object_aclcheck(classId, objectId,
+											aclcheck_tracked[i].roleId,
+											aclcheck_tracked[i].mode);
+
+			if (aclresult != ACLCHECK_OK)
+			{
+				ObjectAddress object;
+
+				object.classId = classId;
+				object.objectId = objectId;
+				object.objectSubId = 0;
+				ereport(ERROR,
+						(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
+						 errmsg("permission denied for %s",
+								getObjectDescription(&object, false))));
+			}
+		}
+	}
+}
+
+
 /*
  * dependencyLockAndCheckObject
  *
- * Lock the object that we are about to record a dependency on.  After it's
- * locked, verify that it hasn't been dropped while we weren't looking.  If it
- * has been dropped, throw an an error.
+ * Lock the object that we are about to record a dependency on. After it's
+ * locked, verify that it hasn't been dropped while we weren't looking. If it
+ * has been dropped, throw an error. Then re-verify any tracked permission
+ * check to close the TOCTOU window.
  *
  * If the caller already holds a lock that conflicts with DROP
- * (AccessShareLock or stronger), this does nothing.  Callers should acquire
- * locks already when they look up the referenced objects, but many callers
- * currently do not.  This is a backstop to make sure that we don't record a
- * bogus reference permanently in the catalogs in that case.  In the future,
- * after we have tightened up all the callers to acquire locks earlier, this
- * could just verify that the object is already locked and throw an error if
- * not.
+ * (AccessShareLock or stronger), this skips lock acquisition entirely.
  */
 static void
 dependencyLockAndCheckObject(Oid classId, Oid objectId)
@@ -773,20 +830,25 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 						   0);
 
 		if (LockHeldByMe(&tag, AccessShareLock, true))
+		{
+			/* Recheck ACL */
+			recheckAcl(classId, objectId);
 			return;
+		}
 
-		/* Assume we should lock the whole object not a sub-object */
+		/* Acquire lock */
 		LockDatabaseObject(classId, objectId, 0, AccessShareLock);
 
-		/*
-		 * Check that the object still exists.  If the catalog has a suitable
-		 * syscache, check that first.
-		 */
+		/* Check that the object still exists */
 		cache = get_object_catcache_oid(classId);
 		if (cache != SYSCACHEID_INVALID)
 		{
 			if (SearchSysCacheExists1(cache, ObjectIdGetDatum(objectId)))
+			{
+				/* Recheck ACL */
+				recheckAcl(classId, objectId);
 				return;
+			}
 		}
 
 		/*
@@ -814,6 +876,9 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 
 		systable_endscan(scan);
 		table_close(rel, AccessShareLock);
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 	else
 	{
@@ -834,14 +899,22 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		Assert(!IsSharedRelation(objectId));
 
 		if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
+		{
+			recheckAcl(classId, objectId);
 			return;
+		}
+
+		/* Acquire lock */
 		LockRelationOid(objectId, AccessShareLock);
 
-		if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
-			return;
-		ereport(ERROR,
-				(errcode(ERRCODE_UNDEFINED_OBJECT),
-				 errmsg("referenced relation was concurrently dropped")));
+		/* Check that the object still exists */
+		if (!SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
+			ereport(ERROR,
+					(errcode(ERRCODE_UNDEFINED_OBJECT),
+					 errmsg("referenced relation was concurrently dropped")));
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 }
 
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..0d0f48715b5 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -20,6 +20,7 @@
 #include "access/twophase.h"
 #include "access/xact.h"
 #include "access/xlog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
@@ -510,11 +511,29 @@ ProcessUtility(PlannedStmt *pstmt,
 			   DestReceiver *dest,
 			   QueryCompletion *qc)
 {
+	int			save_aclcheck_count;
+	bool		was_tracking = aclcheck_tracking_active;
+
 	Assert(IsA(pstmt, PlannedStmt));
 	Assert(pstmt->commandType == CMD_UTILITY);
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
+	/*
+	 * Set up aclcheck tracking. For the top-level call, we initialize. For
+	 * nested calls, we save the current position so we can discard entries
+	 * from this level on return preserving the outer level's entries.
+	 */
+	if (!was_tracking)
+	{
+		aclcheck_track_reset();
+		save_aclcheck_count = 0;
+	}
+	else
+	{
+		save_aclcheck_count = aclcheck_tracked_count;
+	}
+
 	/*
 	 * We provide a function hook variable that lets loadable plugins get
 	 * control when ProcessUtility is called.  Such a plugin would normally
@@ -528,6 +547,15 @@ ProcessUtility(PlannedStmt *pstmt,
 		standard_ProcessUtility(pstmt, queryString, readOnlyTree,
 								context, params, queryEnv,
 								dest, qc);
+
+	/*
+	 * Restore the tracked entry count, discarding entries added at this
+	 * nesting level while preserving outer levels' entries.
+	 */
+	aclcheck_tracked_count = save_aclcheck_count;
+
+	if (!was_tracking)
+		aclcheck_tracking_active = false;
 }
 
 /*
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..0df90ccf42d
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,69 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Track permission checks for revalidation after lock acquisition
+ *	  in dependencyLockAndCheckObject().
+ *
+ * DDL may perform ACL checks on referenced objects without first holding a lock
+ * on them. In that case, the lock is acquired much later, when recording
+ * dependencies.
+ * Track the ACL checks, so that we can re-check them after acquiring the
+ * lock while recording dependencies.
+ *
+ * XXX: consider refactoring so that we perform the name lookup, acquire the
+ * lock, and check ACLs all in unison, like RangeVarGetRelidExtended().
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#include "storage/sinval.h"
+#include "utils/acl.h"
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+	Oid			roleId;
+	AclMode		mode;
+	uint64		inval_count;
+} AclCheckEntry;
+
+extern AclCheckEntry *aclcheck_tracked;
+extern int	aclcheck_tracked_count;
+extern int	aclcheck_tracked_max;
+extern bool aclcheck_tracking_active;
+
+extern void aclcheck_track_reset(void);
+extern void aclcheck_track_grow(void);
+
+/*
+ * Record an aclcheck for later revalidation.
+ *
+ * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Only records when inside an utility statement.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+{
+	if (!aclcheck_tracking_active)
+		return;
+
+	if (aclcheck_tracked_count >= aclcheck_tracked_max)
+		aclcheck_track_grow();
+
+	aclcheck_tracked[aclcheck_tracked_count].classId = classId;
+	aclcheck_tracked[aclcheck_tracked_count].objectId = objectId;
+	aclcheck_tracked[aclcheck_tracked_count].roleId = roleId;
+	aclcheck_tracked[aclcheck_tracked_count].mode = mode;
+	aclcheck_tracked[aclcheck_tracked_count].inval_count = SharedInvalidMessageCounter;
+	aclcheck_tracked_count++;
+}
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/test/isolation/expected/ddl-dependency-locking.out b/src/test/isolation/expected/ddl-dependency-locking.out
index 636de281022..77cc7489170 100644
--- a/src/test/isolation/expected/ddl-dependency-locking.out
+++ b/src/test/isolation/expected/ddl-dependency-locking.out
@@ -1,4 +1,4 @@
-Parsed test spec with 2 sessions
+Parsed test spec with 3 sessions
 
 starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
 step s1_begin: BEGIN;
@@ -135,3 +135,65 @@ step s2_drop_role: DROP ROLE regress_dependency; <waiting ...>
 step s1_commit: COMMIT;
 step s2_drop_role: <... completed>
 ERROR:  role "regress_dependency" cannot be dropped because some objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_as_role_user s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_as_role_user: SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_as_role_user: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_wrapper
+
+starting permutation: s2_begin s2_drop_fdw_spi_func s1_create_server_spi_func s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_spi_func: DROP FOREIGN DATA WRAPPER fdw_spi_func RESTRICT;
+step s1_create_server_spi_func: SET ROLE role_user; CREATE SERVER srv_spi_func FOREIGN DATA WRAPPER fdw_spi_func; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_spi_func: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_spi_func
+
+starting permutation: s2_begin s2_drop_fdw_spi_rollback s1_create_server_spi_rollback s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_spi_rollback: DROP FOREIGN DATA WRAPPER fdw_spi_rollback RESTRICT;
+step s1_create_server_spi_rollback: SET ROLE role_user; CREATE SERVER srv_spi_rollback FOREIGN DATA WRAPPER fdw_spi_rollback; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_spi_rollback: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_spi_rollback
+
+starting permutation: s2_begin s2_drop_fdw_trigger s1_insert_trigger_ddl s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_trigger: DROP FOREIGN DATA WRAPPER fdw_trigger RESTRICT;
+step s1_insert_trigger_ddl: SET ROLE role_user; INSERT INTO trigger_tbl VALUES (1); RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_insert_trigger_ddl: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_trigger
+
+starting permutation: s2_begin s2_drop_fdw_trigger_spi s1_insert_trigger_spi_ddl s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_trigger_spi: DROP FOREIGN DATA WRAPPER fdw_trigger_spi_func RESTRICT;
+step s1_insert_trigger_spi_ddl: SET ROLE role_user; INSERT INTO trigger_spi_tbl VALUES (1); RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_insert_trigger_spi_ddl: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_trigger_spi_func
+
+starting permutation: s2_begin s2_drop_fdw_inner s1_create_server_nested_toctou s3_revoke_both_roles s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_inner: DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT;
+step s1_create_server_nested_toctou: SET ROLE role_user; CREATE SERVER srv_outer FOREIGN DATA WRAPPER fdw_outer; RESET ROLE; <waiting ...>
+step s3_revoke_both_roles: REVOKE role_fdw, role_fdw_inner FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_nested_toctou: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_inner
+
+starting permutation: s2_begin s2_drop_fdw_inner s1_create_server_nested_rollback s3_revoke_role_inner s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_inner: DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT;
+step s1_create_server_nested_rollback: SET ROLE role_user; CREATE SERVER srv_outer_rollback FOREIGN DATA WRAPPER fdw_outer_rollback; RESET ROLE; <waiting ...>
+step s3_revoke_role_inner: REVOKE role_fdw_inner FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_nested_rollback: <... completed>
diff --git a/src/test/isolation/specs/ddl-dependency-locking.spec b/src/test/isolation/specs/ddl-dependency-locking.spec
index de5bd88d35e..72aa97c6dfd 100644
--- a/src/test/isolation/specs/ddl-dependency-locking.spec
+++ b/src/test/isolation/specs/ddl-dependency-locking.spec
@@ -11,7 +11,71 @@ setup
 	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+	CREATE ROLE role_fdw;
+	CREATE ROLE role_user LOGIN;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_wrapper TO role_fdw;
+	GRANT role_fdw TO role_user;
 	CREATE ROLE regress_dependency;
+	CREATE FUNCTION spi_func(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE TEMP TABLE IF NOT EXISTS validator_side_effect(x int)'; END; $$;
+	CREATE FUNCTION spi_func_rollback(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    BEGIN
+	      EXECUTE 'CREATE TEMP TABLE validator_will_rollback(x int)';
+	      RAISE EXCEPTION 'force rollback';
+	    EXCEPTION WHEN OTHERS THEN
+	      NULL;
+	    END;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_spi_func VALIDATOR spi_func;
+	CREATE FOREIGN DATA WRAPPER fdw_spi_rollback VALIDATOR spi_func_rollback;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_spi_func TO role_fdw;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_spi_rollback TO role_fdw;
+	CREATE FOREIGN DATA WRAPPER fdw_trigger;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_trigger TO role_fdw;
+	CREATE FUNCTION trg_create_server() RETURNS trigger
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE SERVER srv_from_trigger FOREIGN DATA WRAPPER fdw_trigger'; RETURN NEW; END; $$;
+	CREATE TABLE trigger_tbl(a int);
+	GRANT INSERT ON trigger_tbl TO role_user;
+	CREATE TRIGGER trg BEFORE INSERT ON trigger_tbl
+	  FOR EACH ROW EXECUTE FUNCTION trg_create_server();
+	CREATE FOREIGN DATA WRAPPER fdw_trigger_spi_func VALIDATOR spi_func;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_trigger_spi_func TO role_fdw;
+	CREATE FUNCTION trg_create_server_spi_func() RETURNS trigger
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE SERVER srv_from_trigger_spi FOREIGN DATA WRAPPER fdw_trigger_spi_func'; RETURN NEW; END; $$;
+	CREATE TABLE trigger_spi_tbl(a int);
+	GRANT INSERT ON trigger_spi_tbl TO role_user;
+	CREATE TRIGGER trg BEFORE INSERT ON trigger_spi_tbl
+	  FOR EACH ROW EXECUTE FUNCTION trg_create_server_spi_func();
+	CREATE FOREIGN DATA WRAPPER fdw_inner;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_inner TO role_fdw;
+	CREATE FUNCTION spi_func_create_server(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    IF $2 = 'pg_catalog.pg_foreign_server'::regclass::oid THEN
+	      EXECUTE 'CREATE SERVER srv_nested_inner FOREIGN DATA WRAPPER fdw_inner';
+	    END IF;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_outer VALIDATOR spi_func_create_server;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_outer TO role_fdw;
+	CREATE ROLE role_fdw_inner;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_inner TO role_fdw_inner;
+	GRANT role_fdw_inner TO role_user;
+	CREATE FUNCTION spi_func_create_server_rollback(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    IF $2 = 'pg_catalog.pg_foreign_server'::regclass::oid THEN
+	      BEGIN
+	        EXECUTE 'CREATE SERVER srv_nested_rollback FOREIGN DATA WRAPPER fdw_inner';
+	        RAISE EXCEPTION 'force rollback';
+	      EXCEPTION WHEN OTHERS THEN
+	        NULL;
+	      END;
+	    END IF;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_outer_rollback VALIDATOR spi_func_create_server_rollback;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_outer_rollback TO role_fdw;
 }
 
 teardown
@@ -24,7 +88,19 @@ teardown
 	DROP FUNCTION IF EXISTS alterschema.falter();
 	DROP DOMAIN IF EXISTS idid;
 	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP SERVER IF EXISTS srv_role_revoked;
+	DROP SERVER IF EXISTS srv_spi_func;
+	DROP SERVER IF EXISTS srv_spi_rollback;
+	DROP SERVER IF EXISTS srv_from_trigger;
+	DROP SERVER IF EXISTS srv_from_trigger_spi;
+	DROP SERVER IF EXISTS srv_from_spi;
+	DROP SERVER IF EXISTS srv_nested_inner;
+	DROP SERVER IF EXISTS srv_nested_rollback;
+	DROP SERVER IF EXISTS srv_outer;
+	DROP SERVER IF EXISTS srv_outer_rollback;
 	DROP TABLE IF EXISTS tabtype;
+	DROP TABLE IF EXISTS trigger_tbl;
+	DROP TABLE IF EXISTS trigger_spi_tbl;
 	DROP SCHEMA IF EXISTS testschema;
 	DROP SCHEMA IF EXISTS alterschema;
 	DROP TYPE IF EXISTS public.foo;
@@ -32,6 +108,22 @@ teardown
 	DROP DOMAIN IF EXISTS id;
 	DROP FUNCTION IF EXISTS f();
 	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_spi_func;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_spi_rollback;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_trigger;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_trigger_spi_func;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_inner;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_outer;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_outer_rollback;
+	DROP FUNCTION IF EXISTS spi_func(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_rollback(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_create_server(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_create_server_rollback(text[], oid);
+	DROP FUNCTION IF EXISTS trg_create_server();
+	DROP FUNCTION IF EXISTS trg_create_server_spi_func();
+	DROP ROLE IF EXISTS role_user;
+	DROP ROLE IF EXISTS role_fdw;
+	DROP ROLE IF EXISTS role_fdw_inner;
 	DROP ROLE regress_dependency;
 }
 
@@ -47,6 +139,13 @@ step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alte
 step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
 step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
 step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_create_server_as_role_user" { SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; }
+step "s1_create_server_spi_func" { SET ROLE role_user; CREATE SERVER srv_spi_func FOREIGN DATA WRAPPER fdw_spi_func; RESET ROLE; }
+step "s1_create_server_spi_rollback" { SET ROLE role_user; CREATE SERVER srv_spi_rollback FOREIGN DATA WRAPPER fdw_spi_rollback; RESET ROLE; }
+step "s1_insert_trigger_ddl" { SET ROLE role_user; INSERT INTO trigger_tbl VALUES (1); RESET ROLE; }
+step "s1_insert_trigger_spi_ddl" { SET ROLE role_user; INSERT INTO trigger_spi_tbl VALUES (1); RESET ROLE; }
+step "s1_create_server_nested_toctou" { SET ROLE role_user; CREATE SERVER srv_outer FOREIGN DATA WRAPPER fdw_outer; RESET ROLE; }
+step "s1_create_server_nested_rollback" { SET ROLE role_user; CREATE SERVER srv_outer_rollback FOREIGN DATA WRAPPER fdw_outer_rollback; RESET ROLE; }
 step "s1_commit" { COMMIT; }
 
 session "s2"
@@ -60,8 +159,20 @@ step "s2_drop_footab_type" { DROP TYPE public.footab; }
 step "s2_drop_function_f" { DROP FUNCTION f(); }
 step "s2_drop_domain_id" { DROP DOMAIN id; }
 step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_drop_fdw_spi_func" { DROP FOREIGN DATA WRAPPER fdw_spi_func RESTRICT; }
+step "s2_drop_fdw_spi_rollback" { DROP FOREIGN DATA WRAPPER fdw_spi_rollback RESTRICT; }
+step "s2_drop_fdw_trigger" { DROP FOREIGN DATA WRAPPER fdw_trigger RESTRICT; }
+step "s2_drop_fdw_trigger_spi" { DROP FOREIGN DATA WRAPPER fdw_trigger_spi_func RESTRICT; }
+step "s2_drop_fdw_inner" { DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT; }
 step "s2_drop_role" { DROP ROLE regress_dependency; }
 step "s2_commit" { COMMIT; }
+step "s2_rollback" { ROLLBACK; }
+
+session "s3"
+
+step "s3_revoke_role" { REVOKE role_fdw FROM role_user; }
+step "s3_revoke_role_inner" { REVOKE role_fdw_inner FROM role_user; }
+step "s3_revoke_both_roles" { REVOKE role_fdw, role_fdw_inner FROM role_user; }
 
 # create function - drop schema
 permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
@@ -102,3 +213,32 @@ permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
 # <OID> was concurrently dropped", contains an OID that is not stable.
 #
 # permutation "s2_begin" "s2_drop_role" "s1_alter_function_owner" "s2_commit"
+
+# Role membership TOCTOU: permission via role revoked during lock wait.
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_as_role_user" "s3_revoke_role" "s2_rollback"
+
+# Role membership TOCTOU with SPI DDL in FDW validator.
+permutation "s2_begin" "s2_drop_fdw_spi_func" "s1_create_server_spi_func" "s3_revoke_role" "s2_rollback"
+
+# Same as above but the validator's SPI DDL fails and rolls back its
+# subtransaction.
+permutation "s2_begin" "s2_drop_fdw_spi_rollback" "s1_create_server_spi_rollback" "s3_revoke_role" "s2_rollback"
+
+# Role membership TOCTOU with DDL triggered from DML: a trigger function does
+# DDL via SPI during INSERT.
+permutation "s2_begin" "s2_drop_fdw_trigger" "s1_insert_trigger_ddl" "s3_revoke_role" "s2_rollback"
+
+# Same as above but the DDL inside the trigger uses an FDW with a SPI validator,
+# combining trigger-initiated DDL with nested SPI.
+permutation "s2_begin" "s2_drop_fdw_trigger_spi" "s1_insert_trigger_spi_ddl" "s3_revoke_role" "s2_rollback"
+
+# TOCTOU on the nested SPI DDL itself: the validator creates a server using
+# fdw_inner, session 2 blocks that by dropping fdw_inner, and the REVOKE
+# removes access to fdw_inner.
+permutation "s2_begin" "s2_drop_fdw_inner" "s1_create_server_nested_toctou" "s3_revoke_both_roles" "s2_rollback"
+
+# Rolled-back nested DDL should not cause the outer to fail: the validator
+# tries to create a server using fdw_inner (via role_fdw_inner) but rolls back.
+# The REVOKE removes role_fdw_inner, but the outer CREATE SERVER only needs
+# role_fdw (for fdw_outer_rollback), so it should succeed.
+permutation "s2_begin" "s2_drop_fdw_inner" "s1_create_server_nested_rollback" "s3_revoke_role_inner" "s2_rollback"
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index 8cf40c87043..cb0cc25bda8 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -19,6 +19,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
-- 
2.47.3

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-16 01:19                                                                                         ` Jeff Davis <pgsql@j-davis.com>
  2026-06-16 10:09                                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2026-06-16 01:19 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Wed, 2026-06-10 at 15:16 +0000, Bertrand Drouvot wrote:
> PFA a new version of v26, it adds a new test as compared to the v26
> previously
> shared.

I'd like to avoid adding lines to AbortTransaction(). Also, I think it
might miss subtransaction aborts, which could be relevant in complex
cases with SPI.

Can you use a structure like:

  ProcessUtility()
  {
      TrackAclTable *prevTrackAclTable = CurrentTrackAclTable;
      /* allocates in CurrentMemoryContext */
      CurrentTrackAclTable = NewTrackAclTable();

      PG_TRY();
      {
           ... rest of ProcessUtility ...
      }
      PG_FINALLY();
      {
          FreeTrackAclTable(CurrentTrackAclTable);
          CurrentTrackAclTable = prevTrackAclTable;
      }
      PG_END_TRY();
  }

That would avoid the need to create a special memory context; you could
just repalloc() the chunk allocated for the table. It would also mean
you don't have to track the stack frames manually with a counter, just
use a local variable.

Also, are you sure that the two call sites for aclcheck_track_record()
are enough? Or do we need checks in e.g. pg_attribute_aclcheck() as
well?

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-16 10:09                                                                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 19:14                                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-16 10:09 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Mon, Jun 15, 2026 at 06:19:19PM -0700, Jeff Davis wrote:
> On Wed, 2026-06-10 at 15:16 +0000, Bertrand Drouvot wrote:
> > PFA a new version of v26, it adds a new test as compared to the v26
> > previously
> > shared.
> 
> I'd like to avoid adding lines to AbortTransaction(). Also, I think it
> might miss subtransaction aborts, which could be relevant in complex
> cases with SPI.
> 
> Can you use a structure like:
> 
>   ProcessUtility()
>   {
>       TrackAclTable *prevTrackAclTable = CurrentTrackAclTable;
>       /* allocates in CurrentMemoryContext */
>       CurrentTrackAclTable = NewTrackAclTable();
> 
>       PG_TRY();
>       {
>            ... rest of ProcessUtility ...
>       }
>       PG_FINALLY();
>       {
>           FreeTrackAclTable(CurrentTrackAclTable);
>           CurrentTrackAclTable = prevTrackAclTable;
>       }
>       PG_END_TRY();
>   }
> 
> That would avoid the need to create a special memory context; you could
> just repalloc() the chunk allocated for the table. It would also mean
> you don't have to track the stack frames manually with a counter, just
> use a local variable.

The advantage of v26 is that it also checked for the outer while checking the
nested (that way a revoke that impacted the outer would fail sooner). That said,
I like your idea: it's more readable and probably less error-prone (don't use
global variable in multiple places and a dedicated counter for nested checks).

So, the attached implements it that way.
It's in 0001. The reason for multiple sub-patches:

> Also, are you sure that the two call sites for aclcheck_track_record()
> are enough? Or do we need checks in e.g. pg_attribute_aclcheck() as
> well?

Currently, the only caller of pg_attribute_aclcheck_ext() that also records
dependencies on the checked object is checkFkeyPermissions(), which already
holds ShareRowExclusiveLock on the referenced table. While ShareRowExclusiveLock
prevents direct REVOKE on the table, it does not prevent role membership revokes.
So 0003 adds pg_attribute_aclcheck_ext to ACL tracking for dependency recording,
which also protects against new DDL callers.

The remaining aclcheck functions (pg_parameter_aclcheck and
pg_largeobject_aclcheck_snapshot) do not need tracking: pg_parameter_aclcheck
checks GUC parameters which are not dependency targets, and
pg_largeobject_aclcheck_snapshot is only called from inv_open() and
has_largeobject_privilege(), neither of which records dependencies.

That said, while looking at checkFkeyPermissions(), I realized that we have a
corner case in 0001.

Indeed, checkFkeyPermissions() first tries pg_class_aclcheck() (which fails for
column-level grants), then falls through to pg_attribute_aclcheck(). But as
aclcheck_track_record() is called for both successful and failed checks, then
the tracked failed entry could trigger a 'permission denied' in recheckAcl() if
catalog invalidations arrived between the check and dependency recording.

0002: fixes it by moving aclcheck_track_record() to after the permission check
succeeds in object_aclcheck_ext() and pg_class_aclcheck_ext(). Indeed, there is
no need to track failed permission checks. It also adds a test that reproduces
the issue by injecting invalidations while the FK creation is paused after the
failed table-level check. The test would fail without the fix in 0002 applied.

0003: adds pg_attribute_aclcheck_ext to ACL tracking for dependency recording.
It adds an attnum field to AclCheckEntry so that recheckAcl() can distinguish
column-level checks from table-level checks and call the appropriate recheck
function. InvalidAttrNumber means whole-object check. 

The sub-patches are to ease the review. They should probably be merged before
being pushed.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v27-0001-Recheck-permissions-after-lock-acquisition-in-de.patch (28.9K, ../../ajEg7PrJYWnmB6zk@bdtpg/2-v27-0001-Recheck-permissions-after-lock-acquisition-in-de.patch)
  download | inline diff:
From 7db50de3c71c269a31bbee0650705f41b59fb0df Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Sat, 30 May 2026 14:35:40 +0000
Subject: [PATCH v27 1/3] Recheck permissions after lock acquisition in
 dependency recording

After dependencyLockAndCheckObject() acquires a lock on a referenced object
(which may have blocked on a concurrent DROP), re-verify any permission check
that was done earlier in the statement. This closes the TOCTOU window where a
REVOKE could land between the original permission check and the dependency
recording.

The approach: record SharedInvalidMessageCounter at the time of the original
aclcheck. After acquiring the lock and verifying the object still exists,
compare the saved counter with the current value. If it changed (meaning
catalog invalidations arrived since the original check), re-verify the
permission. Since the OID is fixed (no name re-resolution), a failure is
definitive and no retry loop is needed.

Each ProcessUtility() call allocates a TrackAclTable in CurrentMemoryContext
and saves the previous one in a local variable. A PG_TRY/PG_FINALLY block
ensures that the table is freed and the previous pointer restored on both
normal return and error. This forms an implicit stack: each nesting level
tracks only its own ACL checks, and the outer level's entries remain
undisturbed. No dedicated memory context or AbortTransaction cleanup is needed.

Recording is gated by checking CurrentTrackAclTable != NULL, so DML and queries
pay only a single pointer test.

Alternatives considered:

- To avoid allocating memory for each statement, keep the array in
TopMemoryContext and never free it (only resetting the count). But that left the
high-water mark allocated for the lifetime of the backend.

- Passing privilege info (roleId, mode) as extra arguments through the
  dependency recording APIs (recordDependencyOn, recordMultipleDependencies,
  etc.) was discarded because expression-based dependencies
  (recordDependencyOnExpr, find_expr_references_walker) discover objects by
  walking expression trees: the caller never sees individual objects and cannot
  attach privilege info to them.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/aclchk.c                  |  32 ++++
 src/backend/catalog/pg_depend.c               | 104 ++++++++++++-
 src/backend/tcop/utility.c                    |  41 +++--
 src/include/catalog/aclcheck_track.h          |  80 ++++++++++
 .../expected/ddl-dependency-locking.out       |  64 +++++++-
 .../specs/ddl-dependency-locking.spec         | 140 ++++++++++++++++++
 src/tools/pgindent/typedefs.list              |   2 +
 7 files changed, 441 insertions(+), 22 deletions(-)
  20.0% src/backend/catalog/
   6.7% src/backend/tcop/
  11.7% src/include/catalog/
  20.5% src/test/isolation/expected/
  40.7% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 007ede997c5..ab19db9d789 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -44,6 +44,7 @@
 #include "access/sysattr.h"
 #include "access/tableam.h"
 #include "access/xact.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
@@ -84,6 +85,10 @@
 #include "utils/rel.h"
 #include "utils/syscache.h"
 
+#define ACLCHECK_TRACK_INITIAL_SIZE 64
+
+TrackAclTable *CurrentTrackAclTable = NULL;
+
 /*
  * Internal format used by ALTER DEFAULT PRIVILEGES.
  */
@@ -3891,6 +3896,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4093,6 +4099,7 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5036,3 +5043,28 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Allocate a new tracking table in CurrentMemoryContext.
+ */
+TrackAclTable *
+CreateTrackAclTable(void)
+{
+	TrackAclTable *acltable = (TrackAclTable *) palloc(sizeof(TrackAclTable));
+
+	acltable->entries = (AclCheckEntry *)
+		palloc(ACLCHECK_TRACK_INITIAL_SIZE * sizeof(AclCheckEntry));
+	acltable->max = ACLCHECK_TRACK_INITIAL_SIZE;
+	acltable->count = 0;
+	return acltable;
+}
+
+/*
+ * Free a tracking table.
+ */
+void
+FreeTrackAclTable(TrackAclTable *acltable)
+{
+	pfree(acltable->entries);
+	pfree(acltable);
+}
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 9a7a401aced..912c92e8fef 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -17,6 +17,7 @@
 #include "access/genam.h"
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
@@ -29,6 +30,8 @@
 #include "miscadmin.h"
 #include "storage/lmgr.h"
 #include "storage/lock.h"
+#include "storage/sinval.h"
+#include "utils/acl.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -38,6 +41,7 @@
 
 static bool isObjectPinned(const ObjectAddress *object);
 static void dependencyLockAndCheckObject(Oid classId, Oid objectId);
+static void recheckAcl(Oid classId, Oid objectId);
 
 
 /*
@@ -732,12 +736,76 @@ isObjectPinned(const ObjectAddress *object)
 }
 
 
+/*
+ * recheckAcl()
+ *
+ * Re-verify all tracked permission checks on the given object.
+ *
+ * Called after acquiring the lock and verifying the object still exists.
+ * If permission checks were tracked for this object and catalog
+ * invalidations arrived since the original checks, re-verify them all.
+ * This closes the TOCTOU window where a REVOKE could land between the
+ * original permission check and the dependency recording.
+ *
+ * Multiple checks may have been done on the same object with different
+ * modes or roles, so we iterate through all matching entries.
+ *
+ * Since we don't re-resolve names (the OID is fixed), there is no need for
+ * a retry loop here. If a recheck fails, it's a definitive failure.
+ *
+ * The linear scan over the tracking array is O(n) in the number of tracked
+ * entries, but that's fine since a typical DDL statement tracks only a few
+ * objects.
+ */
+static void
+recheckAcl(Oid classId, Oid objectId)
+{
+	TrackAclTable *acltable = CurrentTrackAclTable;
+
+	if (acltable == NULL)
+		return;
+
+	for (int i = acltable->count - 1; i >= 0; i--)
+	{
+		if (acltable->entries[i].classId == classId &&
+			acltable->entries[i].objectId == objectId &&
+			acltable->entries[i].inval_count != SharedInvalidMessageCounter)
+		{
+			AclResult	aclresult;
+
+			if (classId == RelationRelationId)
+				aclresult = pg_class_aclcheck(objectId,
+											  acltable->entries[i].roleId,
+											  acltable->entries[i].mode);
+			else
+				aclresult = object_aclcheck(classId, objectId,
+											acltable->entries[i].roleId,
+											acltable->entries[i].mode);
+
+			if (aclresult != ACLCHECK_OK)
+			{
+				ObjectAddress object;
+
+				object.classId = classId;
+				object.objectId = objectId;
+				object.objectSubId = 0;
+				ereport(ERROR,
+						(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
+						 errmsg("permission denied for %s",
+								getObjectDescription(&object, false))));
+			}
+		}
+	}
+}
+
+
 /*
  * dependencyLockAndCheckObject
  *
- * Lock the object that we are about to record a dependency on.  After it's
- * locked, verify that it hasn't been dropped while we weren't looking.  If it
- * has been dropped, throw an an error.
+ * Lock the object that we are about to record a dependency on. After it's
+ * locked, verify that it hasn't been dropped while we weren't looking. If it
+ * has been dropped, throw an error. Then re-verify any tracked permission
+ * check to close the TOCTOU window.
  *
  * If the caller already holds a lock that conflicts with DROP
  * (AccessShareLock or stronger), this does nothing.  Callers should acquire
@@ -773,7 +841,11 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 						   0);
 
 		if (LockHeldByMe(&tag, AccessShareLock, true))
+		{
+			/* Recheck ACL */
+			recheckAcl(classId, objectId);
 			return;
+		}
 
 		/* Assume we should lock the whole object not a sub-object */
 		LockDatabaseObject(classId, objectId, 0, AccessShareLock);
@@ -786,7 +858,11 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		if (cache != SYSCACHEID_INVALID)
 		{
 			if (SearchSysCacheExists1(cache, ObjectIdGetDatum(objectId)))
+			{
+				/* Recheck ACL */
+				recheckAcl(classId, objectId);
 				return;
+			}
 		}
 
 		/*
@@ -814,6 +890,9 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 
 		systable_endscan(scan);
 		table_close(rel, AccessShareLock);
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 	else
 	{
@@ -834,14 +913,23 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		Assert(!IsSharedRelation(objectId));
 
 		if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
+		{
+			/* Recheck ACL */
+			recheckAcl(classId, objectId);
 			return;
+		}
+
+		/* Acquire lock */
 		LockRelationOid(objectId, AccessShareLock);
 
-		if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
-			return;
-		ereport(ERROR,
-				(errcode(ERRCODE_UNDEFINED_OBJECT),
-				 errmsg("referenced relation was concurrently dropped")));
+		/* Check that the object still exists */
+		if (!SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
+			ereport(ERROR,
+					(errcode(ERRCODE_UNDEFINED_OBJECT),
+					 errmsg("referenced relation was concurrently dropped")));
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 }
 
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..1fad5d9a78d 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -20,6 +20,7 @@
 #include "access/twophase.h"
 #include "access/xact.h"
 #include "access/xlog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
@@ -510,24 +511,38 @@ ProcessUtility(PlannedStmt *pstmt,
 			   DestReceiver *dest,
 			   QueryCompletion *qc)
 {
+	TrackAclTable *prevTrackAclTable = CurrentTrackAclTable;
+
 	Assert(IsA(pstmt, PlannedStmt));
 	Assert(pstmt->commandType == CMD_UTILITY);
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
-	/*
-	 * We provide a function hook variable that lets loadable plugins get
-	 * control when ProcessUtility is called.  Such a plugin would normally
-	 * call standard_ProcessUtility().
-	 */
-	if (ProcessUtility_hook)
-		(*ProcessUtility_hook) (pstmt, queryString, readOnlyTree,
-								context, params, queryEnv,
-								dest, qc);
-	else
-		standard_ProcessUtility(pstmt, queryString, readOnlyTree,
-								context, params, queryEnv,
-								dest, qc);
+	/* Allocate a fresh acl tracking table for this utility statement. */
+	CurrentTrackAclTable = CreateTrackAclTable();
+
+	PG_TRY();
+	{
+		/*
+		 * We provide a function hook variable that lets loadable plugins get
+		 * control when ProcessUtility is called.  Such a plugin would
+		 * normally call standard_ProcessUtility().
+		 */
+		if (ProcessUtility_hook)
+			(*ProcessUtility_hook) (pstmt, queryString, readOnlyTree,
+									context, params, queryEnv,
+									dest, qc);
+		else
+			standard_ProcessUtility(pstmt, queryString, readOnlyTree,
+									context, params, queryEnv,
+									dest, qc);
+	}
+	PG_FINALLY();
+	{
+		FreeTrackAclTable(CurrentTrackAclTable);
+		CurrentTrackAclTable = prevTrackAclTable;
+	}
+	PG_END_TRY();
 }
 
 /*
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..d994cf7889b
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,80 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Track permission checks for revalidation after lock acquisition
+ *	  in dependencyLockAndCheckObject().
+ *
+ * DDL may perform ACL checks on referenced objects without first holding a lock
+ * on them. In that case, the lock is acquired much later, when recording
+ * dependencies.
+ * Track the ACL checks, so that we can re-check them after acquiring the
+ * lock while recording dependencies.
+ *
+ * XXX: consider refactoring so that we perform the name lookup, acquire the
+ * lock, and check ACLs all in unison, like RangeVarGetRelidExtended().
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#include "storage/sinval.h"
+#include "utils/acl.h"
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+	Oid			roleId;
+	AclMode		mode;
+	uint64		inval_count;
+} AclCheckEntry;
+
+typedef struct TrackAclTable
+{
+	AclCheckEntry *entries;
+	int			count;
+	int			max;
+} TrackAclTable;
+
+extern TrackAclTable *CurrentTrackAclTable;
+
+extern TrackAclTable *CreateTrackAclTable(void);
+extern void FreeTrackAclTable(TrackAclTable *acltable);
+
+/*
+ * Record an aclcheck for later revalidation.
+ *
+ * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Only records when inside an utility statement.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+{
+	TrackAclTable *acltable = CurrentTrackAclTable;
+	AclCheckEntry *entry;
+
+	if (acltable == NULL)
+		return;
+
+	if (acltable->count >= acltable->max)
+	{
+		acltable->max *= 2;
+		acltable->entries = (AclCheckEntry *)
+			repalloc(acltable->entries, acltable->max * sizeof(AclCheckEntry));
+	}
+
+	entry = &acltable->entries[acltable->count++];
+	entry->classId = classId;
+	entry->objectId = objectId;
+	entry->roleId = roleId;
+	entry->mode = mode;
+	entry->inval_count = SharedInvalidMessageCounter;
+}
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/test/isolation/expected/ddl-dependency-locking.out b/src/test/isolation/expected/ddl-dependency-locking.out
index 636de281022..77cc7489170 100644
--- a/src/test/isolation/expected/ddl-dependency-locking.out
+++ b/src/test/isolation/expected/ddl-dependency-locking.out
@@ -1,4 +1,4 @@
-Parsed test spec with 2 sessions
+Parsed test spec with 3 sessions
 
 starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
 step s1_begin: BEGIN;
@@ -135,3 +135,65 @@ step s2_drop_role: DROP ROLE regress_dependency; <waiting ...>
 step s1_commit: COMMIT;
 step s2_drop_role: <... completed>
 ERROR:  role "regress_dependency" cannot be dropped because some objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_as_role_user s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_as_role_user: SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_as_role_user: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_wrapper
+
+starting permutation: s2_begin s2_drop_fdw_spi_func s1_create_server_spi_func s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_spi_func: DROP FOREIGN DATA WRAPPER fdw_spi_func RESTRICT;
+step s1_create_server_spi_func: SET ROLE role_user; CREATE SERVER srv_spi_func FOREIGN DATA WRAPPER fdw_spi_func; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_spi_func: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_spi_func
+
+starting permutation: s2_begin s2_drop_fdw_spi_rollback s1_create_server_spi_rollback s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_spi_rollback: DROP FOREIGN DATA WRAPPER fdw_spi_rollback RESTRICT;
+step s1_create_server_spi_rollback: SET ROLE role_user; CREATE SERVER srv_spi_rollback FOREIGN DATA WRAPPER fdw_spi_rollback; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_spi_rollback: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_spi_rollback
+
+starting permutation: s2_begin s2_drop_fdw_trigger s1_insert_trigger_ddl s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_trigger: DROP FOREIGN DATA WRAPPER fdw_trigger RESTRICT;
+step s1_insert_trigger_ddl: SET ROLE role_user; INSERT INTO trigger_tbl VALUES (1); RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_insert_trigger_ddl: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_trigger
+
+starting permutation: s2_begin s2_drop_fdw_trigger_spi s1_insert_trigger_spi_ddl s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_trigger_spi: DROP FOREIGN DATA WRAPPER fdw_trigger_spi_func RESTRICT;
+step s1_insert_trigger_spi_ddl: SET ROLE role_user; INSERT INTO trigger_spi_tbl VALUES (1); RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_insert_trigger_spi_ddl: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_trigger_spi_func
+
+starting permutation: s2_begin s2_drop_fdw_inner s1_create_server_nested_toctou s3_revoke_both_roles s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_inner: DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT;
+step s1_create_server_nested_toctou: SET ROLE role_user; CREATE SERVER srv_outer FOREIGN DATA WRAPPER fdw_outer; RESET ROLE; <waiting ...>
+step s3_revoke_both_roles: REVOKE role_fdw, role_fdw_inner FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_nested_toctou: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_inner
+
+starting permutation: s2_begin s2_drop_fdw_inner s1_create_server_nested_rollback s3_revoke_role_inner s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_inner: DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT;
+step s1_create_server_nested_rollback: SET ROLE role_user; CREATE SERVER srv_outer_rollback FOREIGN DATA WRAPPER fdw_outer_rollback; RESET ROLE; <waiting ...>
+step s3_revoke_role_inner: REVOKE role_fdw_inner FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_nested_rollback: <... completed>
diff --git a/src/test/isolation/specs/ddl-dependency-locking.spec b/src/test/isolation/specs/ddl-dependency-locking.spec
index de5bd88d35e..72aa97c6dfd 100644
--- a/src/test/isolation/specs/ddl-dependency-locking.spec
+++ b/src/test/isolation/specs/ddl-dependency-locking.spec
@@ -11,7 +11,71 @@ setup
 	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+	CREATE ROLE role_fdw;
+	CREATE ROLE role_user LOGIN;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_wrapper TO role_fdw;
+	GRANT role_fdw TO role_user;
 	CREATE ROLE regress_dependency;
+	CREATE FUNCTION spi_func(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE TEMP TABLE IF NOT EXISTS validator_side_effect(x int)'; END; $$;
+	CREATE FUNCTION spi_func_rollback(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    BEGIN
+	      EXECUTE 'CREATE TEMP TABLE validator_will_rollback(x int)';
+	      RAISE EXCEPTION 'force rollback';
+	    EXCEPTION WHEN OTHERS THEN
+	      NULL;
+	    END;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_spi_func VALIDATOR spi_func;
+	CREATE FOREIGN DATA WRAPPER fdw_spi_rollback VALIDATOR spi_func_rollback;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_spi_func TO role_fdw;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_spi_rollback TO role_fdw;
+	CREATE FOREIGN DATA WRAPPER fdw_trigger;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_trigger TO role_fdw;
+	CREATE FUNCTION trg_create_server() RETURNS trigger
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE SERVER srv_from_trigger FOREIGN DATA WRAPPER fdw_trigger'; RETURN NEW; END; $$;
+	CREATE TABLE trigger_tbl(a int);
+	GRANT INSERT ON trigger_tbl TO role_user;
+	CREATE TRIGGER trg BEFORE INSERT ON trigger_tbl
+	  FOR EACH ROW EXECUTE FUNCTION trg_create_server();
+	CREATE FOREIGN DATA WRAPPER fdw_trigger_spi_func VALIDATOR spi_func;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_trigger_spi_func TO role_fdw;
+	CREATE FUNCTION trg_create_server_spi_func() RETURNS trigger
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE SERVER srv_from_trigger_spi FOREIGN DATA WRAPPER fdw_trigger_spi_func'; RETURN NEW; END; $$;
+	CREATE TABLE trigger_spi_tbl(a int);
+	GRANT INSERT ON trigger_spi_tbl TO role_user;
+	CREATE TRIGGER trg BEFORE INSERT ON trigger_spi_tbl
+	  FOR EACH ROW EXECUTE FUNCTION trg_create_server_spi_func();
+	CREATE FOREIGN DATA WRAPPER fdw_inner;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_inner TO role_fdw;
+	CREATE FUNCTION spi_func_create_server(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    IF $2 = 'pg_catalog.pg_foreign_server'::regclass::oid THEN
+	      EXECUTE 'CREATE SERVER srv_nested_inner FOREIGN DATA WRAPPER fdw_inner';
+	    END IF;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_outer VALIDATOR spi_func_create_server;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_outer TO role_fdw;
+	CREATE ROLE role_fdw_inner;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_inner TO role_fdw_inner;
+	GRANT role_fdw_inner TO role_user;
+	CREATE FUNCTION spi_func_create_server_rollback(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    IF $2 = 'pg_catalog.pg_foreign_server'::regclass::oid THEN
+	      BEGIN
+	        EXECUTE 'CREATE SERVER srv_nested_rollback FOREIGN DATA WRAPPER fdw_inner';
+	        RAISE EXCEPTION 'force rollback';
+	      EXCEPTION WHEN OTHERS THEN
+	        NULL;
+	      END;
+	    END IF;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_outer_rollback VALIDATOR spi_func_create_server_rollback;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_outer_rollback TO role_fdw;
 }
 
 teardown
@@ -24,7 +88,19 @@ teardown
 	DROP FUNCTION IF EXISTS alterschema.falter();
 	DROP DOMAIN IF EXISTS idid;
 	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP SERVER IF EXISTS srv_role_revoked;
+	DROP SERVER IF EXISTS srv_spi_func;
+	DROP SERVER IF EXISTS srv_spi_rollback;
+	DROP SERVER IF EXISTS srv_from_trigger;
+	DROP SERVER IF EXISTS srv_from_trigger_spi;
+	DROP SERVER IF EXISTS srv_from_spi;
+	DROP SERVER IF EXISTS srv_nested_inner;
+	DROP SERVER IF EXISTS srv_nested_rollback;
+	DROP SERVER IF EXISTS srv_outer;
+	DROP SERVER IF EXISTS srv_outer_rollback;
 	DROP TABLE IF EXISTS tabtype;
+	DROP TABLE IF EXISTS trigger_tbl;
+	DROP TABLE IF EXISTS trigger_spi_tbl;
 	DROP SCHEMA IF EXISTS testschema;
 	DROP SCHEMA IF EXISTS alterschema;
 	DROP TYPE IF EXISTS public.foo;
@@ -32,6 +108,22 @@ teardown
 	DROP DOMAIN IF EXISTS id;
 	DROP FUNCTION IF EXISTS f();
 	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_spi_func;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_spi_rollback;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_trigger;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_trigger_spi_func;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_inner;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_outer;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_outer_rollback;
+	DROP FUNCTION IF EXISTS spi_func(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_rollback(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_create_server(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_create_server_rollback(text[], oid);
+	DROP FUNCTION IF EXISTS trg_create_server();
+	DROP FUNCTION IF EXISTS trg_create_server_spi_func();
+	DROP ROLE IF EXISTS role_user;
+	DROP ROLE IF EXISTS role_fdw;
+	DROP ROLE IF EXISTS role_fdw_inner;
 	DROP ROLE regress_dependency;
 }
 
@@ -47,6 +139,13 @@ step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alte
 step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
 step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
 step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_create_server_as_role_user" { SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; }
+step "s1_create_server_spi_func" { SET ROLE role_user; CREATE SERVER srv_spi_func FOREIGN DATA WRAPPER fdw_spi_func; RESET ROLE; }
+step "s1_create_server_spi_rollback" { SET ROLE role_user; CREATE SERVER srv_spi_rollback FOREIGN DATA WRAPPER fdw_spi_rollback; RESET ROLE; }
+step "s1_insert_trigger_ddl" { SET ROLE role_user; INSERT INTO trigger_tbl VALUES (1); RESET ROLE; }
+step "s1_insert_trigger_spi_ddl" { SET ROLE role_user; INSERT INTO trigger_spi_tbl VALUES (1); RESET ROLE; }
+step "s1_create_server_nested_toctou" { SET ROLE role_user; CREATE SERVER srv_outer FOREIGN DATA WRAPPER fdw_outer; RESET ROLE; }
+step "s1_create_server_nested_rollback" { SET ROLE role_user; CREATE SERVER srv_outer_rollback FOREIGN DATA WRAPPER fdw_outer_rollback; RESET ROLE; }
 step "s1_commit" { COMMIT; }
 
 session "s2"
@@ -60,8 +159,20 @@ step "s2_drop_footab_type" { DROP TYPE public.footab; }
 step "s2_drop_function_f" { DROP FUNCTION f(); }
 step "s2_drop_domain_id" { DROP DOMAIN id; }
 step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_drop_fdw_spi_func" { DROP FOREIGN DATA WRAPPER fdw_spi_func RESTRICT; }
+step "s2_drop_fdw_spi_rollback" { DROP FOREIGN DATA WRAPPER fdw_spi_rollback RESTRICT; }
+step "s2_drop_fdw_trigger" { DROP FOREIGN DATA WRAPPER fdw_trigger RESTRICT; }
+step "s2_drop_fdw_trigger_spi" { DROP FOREIGN DATA WRAPPER fdw_trigger_spi_func RESTRICT; }
+step "s2_drop_fdw_inner" { DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT; }
 step "s2_drop_role" { DROP ROLE regress_dependency; }
 step "s2_commit" { COMMIT; }
+step "s2_rollback" { ROLLBACK; }
+
+session "s3"
+
+step "s3_revoke_role" { REVOKE role_fdw FROM role_user; }
+step "s3_revoke_role_inner" { REVOKE role_fdw_inner FROM role_user; }
+step "s3_revoke_both_roles" { REVOKE role_fdw, role_fdw_inner FROM role_user; }
 
 # create function - drop schema
 permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
@@ -102,3 +213,32 @@ permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
 # <OID> was concurrently dropped", contains an OID that is not stable.
 #
 # permutation "s2_begin" "s2_drop_role" "s1_alter_function_owner" "s2_commit"
+
+# Role membership TOCTOU: permission via role revoked during lock wait.
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_as_role_user" "s3_revoke_role" "s2_rollback"
+
+# Role membership TOCTOU with SPI DDL in FDW validator.
+permutation "s2_begin" "s2_drop_fdw_spi_func" "s1_create_server_spi_func" "s3_revoke_role" "s2_rollback"
+
+# Same as above but the validator's SPI DDL fails and rolls back its
+# subtransaction.
+permutation "s2_begin" "s2_drop_fdw_spi_rollback" "s1_create_server_spi_rollback" "s3_revoke_role" "s2_rollback"
+
+# Role membership TOCTOU with DDL triggered from DML: a trigger function does
+# DDL via SPI during INSERT.
+permutation "s2_begin" "s2_drop_fdw_trigger" "s1_insert_trigger_ddl" "s3_revoke_role" "s2_rollback"
+
+# Same as above but the DDL inside the trigger uses an FDW with a SPI validator,
+# combining trigger-initiated DDL with nested SPI.
+permutation "s2_begin" "s2_drop_fdw_trigger_spi" "s1_insert_trigger_spi_ddl" "s3_revoke_role" "s2_rollback"
+
+# TOCTOU on the nested SPI DDL itself: the validator creates a server using
+# fdw_inner, session 2 blocks that by dropping fdw_inner, and the REVOKE
+# removes access to fdw_inner.
+permutation "s2_begin" "s2_drop_fdw_inner" "s1_create_server_nested_toctou" "s3_revoke_both_roles" "s2_rollback"
+
+# Rolled-back nested DDL should not cause the outer to fail: the validator
+# tries to create a server using fdw_inner (via role_fdw_inner) but rolls back.
+# The REVOKE removes role_fdw_inner, but the outer CREATE SERVER only needs
+# role_fdw (for fdw_outer_rollback), so it should succeed.
+permutation "s2_begin" "s2_drop_fdw_inner" "s1_create_server_nested_rollback" "s3_revoke_role_inner" "s2_rollback"
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index f9eb23e52c9..637e15b38b3 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -19,6 +19,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
@@ -3226,6 +3227,7 @@ ToastedAttribute
 TocEntry
 TokenAuxData
 TokenizedAuthLine
+TrackAclTable
 TrackItem
 TransApplyAction
 TransInvalidationInfo
-- 
2.34.1

  [text/x-diff] v27-0002-Only-track-successful-ACL-checks-in-aclcheck_tra.patch (8.0K, ../../ajEg7PrJYWnmB6zk@bdtpg/3-v27-0002-Only-track-successful-ACL-checks-in-aclcheck_tra.patch)
  download | inline diff:
From 3a823115cc9756650fc46c42d3182ac707f771f1 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Tue, 16 Jun 2026 07:31:28 +0000
Subject: [PATCH v27 2/3] Only track successful ACL checks in
 aclcheck_track_record()

Previously, aclcheck_track_record() was called before the actual permission
check, so both successful and failed checks were recorded. This caused a
problem with column-level REFERENCES: checkFkeyPermissions() first tries
pg_class_aclcheck() (which fails for column-level grants), then falls through
to pg_attribute_aclcheck() (which succeeds). The tracked failed entry could
trigger a spurious 'permission denied' in recheckAcl() if catalog
invalidations arrived between the check and dependency recording.

Fix by moving aclcheck_track_record() to after the permission check succeeds
in object_aclcheck_ext() and pg_class_aclcheck_ext().

Add an injection point in checkFkeyPermissions() and a test that reproduces
the issue by injecting invalidations while the FK creation is paused after
the failed table-level check.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/aclchk.c                  |  8 ++-
 src/backend/commands/tablecmds.c              |  4 ++
 src/test/modules/injection_points/Makefile    |  3 +-
 .../expected/fk_column_ref.out                | 33 +++++++++++
 src/test/modules/injection_points/meson.build |  1 +
 .../injection_points/specs/fk_column_ref.spec | 56 +++++++++++++++++++
 6 files changed, 102 insertions(+), 3 deletions(-)
   8.0% src/backend/catalog/
   3.2% src/backend/commands/
  27.0% src/test/modules/injection_points/expected/
  58.9% src/test/modules/injection_points/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index ab19db9d789..02c4489f0c4 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -3896,10 +3896,12 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
-	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
+	{
+		aclcheck_track_record(classid, objectid, roleid, mode);
 		return ACLCHECK_OK;
+	}
 	else
 		return ACLCHECK_NO_PRIV;
 }
@@ -4099,10 +4101,12 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
-	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
+	{
+		aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 		return ACLCHECK_OK;
+	}
 	else
 		return ACLCHECK_NO_PRIV;
 }
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 38f9ffcd04f..2b456907575 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -101,6 +101,7 @@
 #include "utils/acl.h"
 #include "utils/builtins.h"
 #include "utils/fmgroids.h"
+#include "utils/injection_point.h"
 #include "utils/inval.h"
 #include "utils/lsyscache.h"
 #include "utils/memutils.h"
@@ -13929,6 +13930,9 @@ checkFkeyPermissions(Relation rel, int16 *attnums, int natts)
 								  ACL_REFERENCES);
 	if (aclresult == ACLCHECK_OK)
 		return;
+
+	INJECTION_POINT("checkFkeyPermissions-after-table-acl-fail", NULL);
+
 	/* Else we must have REFERENCES on each column */
 	for (i = 0; i < natts; i++)
 	{
diff --git a/src/test/modules/injection_points/Makefile b/src/test/modules/injection_points/Makefile
index c01d2fb095c..2af9d045555 100644
--- a/src/test/modules/injection_points/Makefile
+++ b/src/test/modules/injection_points/Makefile
@@ -19,7 +19,8 @@ ISOLATION = basic \
 	    repack_temporal_multirange \
 	    repack_toast \
 	    syscache-update-pruned \
-	    heap_lock_update
+	    heap_lock_update \
+	    fk_column_ref
 
 # some isolation tests require wal_level=replica
 ISOLATION_OPTS = --temp-config $(top_srcdir)/src/test/modules/injection_points/extra.conf
diff --git a/src/test/modules/injection_points/expected/fk_column_ref.out b/src/test/modules/injection_points/expected/fk_column_ref.out
new file mode 100644
index 00000000000..5f33cc1d1a2
--- /dev/null
+++ b/src/test/modules/injection_points/expected/fk_column_ref.out
@@ -0,0 +1,33 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_attach s1_add_fk s2_invalidate_and_wakeup
+step s1_attach: 
+	SELECT injection_points_set_local();
+	SELECT injection_points_attach('checkFkeyPermissions-after-table-acl-fail', 'wait');
+
+injection_points_set_local
+--------------------------
+                          
+(1 row)
+
+injection_points_attach
+-----------------------
+                       
+(1 row)
+
+step s1_add_fk: 
+	SET ROLE role_fk_tester;
+	ALTER TABLE fk_source ADD FOREIGN KEY (ref_id) REFERENCES fk_ref_target(id);
+	RESET ROLE;
+ <waiting ...>
+step s2_invalidate_and_wakeup: 
+	GRANT SELECT ON produce_inval TO role_fk_tester;
+	REVOKE SELECT ON produce_inval FROM role_fk_tester;
+	SELECT injection_points_wakeup('checkFkeyPermissions-after-table-acl-fail');
+
+injection_points_wakeup
+-----------------------
+                       
+(1 row)
+
+step s1_add_fk: <... completed>
diff --git a/src/test/modules/injection_points/meson.build b/src/test/modules/injection_points/meson.build
index 59dba1cb023..6c7a48edf77 100644
--- a/src/test/modules/injection_points/meson.build
+++ b/src/test/modules/injection_points/meson.build
@@ -51,6 +51,7 @@ tests += {
       'repack_toast',
       'syscache-update-pruned',
       'heap_lock_update',
+      'fk_column_ref',
     ],
     'runningcheck': false, # see syscache-update-pruned
     # Some tests wait for all snapshots, so avoid parallel execution
diff --git a/src/test/modules/injection_points/specs/fk_column_ref.spec b/src/test/modules/injection_points/specs/fk_column_ref.spec
new file mode 100644
index 00000000000..4e9307c913b
--- /dev/null
+++ b/src/test/modules/injection_points/specs/fk_column_ref.spec
@@ -0,0 +1,56 @@
+# Test that column-level REFERENCES does not trigger a false recheck failure.
+#
+# When a user has only column-level REFERENCES (not table-level),
+# checkFkeyPermissions() calls pg_class_aclcheck() which fails then falls
+# through to pg_attribute_aclcheck() which succeeds. If catalog invalidations
+# arrive before dependency recording, recheckAcl() must not spuriously fail on
+# the tracked failed check (it should not be tracked).
+
+setup
+{
+	CREATE EXTENSION injection_points;
+	CREATE TABLE fk_ref_target(id int PRIMARY KEY);
+	INSERT INTO fk_ref_target VALUES (1);
+	CREATE TABLE produce_inval(x int);
+	CREATE ROLE role_fk_tester;
+	GRANT REFERENCES(id) ON fk_ref_target TO role_fk_tester;
+	GRANT CREATE ON SCHEMA public TO role_fk_tester;
+	GRANT SELECT ON fk_ref_target TO role_fk_tester;
+	SET ROLE role_fk_tester;
+	CREATE TABLE fk_source(ref_id int);
+	INSERT INTO fk_source VALUES (1);
+	RESET ROLE;
+}
+
+teardown
+{
+	DROP TABLE IF EXISTS fk_source;
+	DROP TABLE IF EXISTS fk_ref_target;
+	DROP TABLE IF EXISTS produce_inval;
+	REVOKE CREATE ON SCHEMA public FROM role_fk_tester;
+	DROP ROLE role_fk_tester;
+	DROP EXTENSION injection_points;
+}
+
+session "s1"
+step "s1_attach" {
+	SELECT injection_points_set_local();
+	SELECT injection_points_attach('checkFkeyPermissions-after-table-acl-fail', 'wait');
+}
+step "s1_add_fk" {
+	SET ROLE role_fk_tester;
+	ALTER TABLE fk_source ADD FOREIGN KEY (ref_id) REFERENCES fk_ref_target(id);
+	RESET ROLE;
+}
+
+session "s2"
+step "s2_invalidate_and_wakeup" {
+	GRANT SELECT ON produce_inval TO role_fk_tester;
+	REVOKE SELECT ON produce_inval FROM role_fk_tester;
+	SELECT injection_points_wakeup('checkFkeyPermissions-after-table-acl-fail');
+}
+
+# s1 attaches the wait point, then starts the FK creation which blocks
+# after the failed pg_class_aclcheck. s2 generates invalidations and
+# wakes s1. The FK creation must succeed despite the invalidations.
+permutation "s1_attach" "s1_add_fk" "s2_invalidate_and_wakeup"
-- 
2.34.1

  [text/x-diff] v27-0003-Add-pg_attribute_aclcheck_ext-to-ACL-tracking-fo.patch (5.0K, ../../ajEg7PrJYWnmB6zk@bdtpg/4-v27-0003-Add-pg_attribute_aclcheck_ext-to-ACL-tracking-fo.patch)
  download | inline diff:
From 8665017b0bbf42d867ebebe90a80724dfdb84847 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Tue, 16 Jun 2026 07:33:39 +0000
Subject: [PATCH v27 3/3] Add pg_attribute_aclcheck_ext to ACL tracking for
 dependency recording

Add an attnum field to AclCheckEntry so that recheckAcl() can distinguish
column-level checks from table-level checks and call the appropriate recheck
function. InvalidAttrNumber means whole-object check.

This also adds tracking to pg_attribute_aclcheck_ext(), so that future DDL
paths using column-level privileges will automatically get TOCTOU protection
without needing a pre-existing lock on the table.

Currently, the only caller of pg_attribute_aclcheck_ext() that also records
dependencies on the checked object is checkFkeyPermissions(), which holds
ShareRowExclusiveLock on the referenced table. While this prevents concurrent
REVOKE ON the table itself, it does not prevent concurrent role membership
revokes. Adding tracking here provides protection against that case and future
DDL callers.

The remaining aclcheck functions (pg_parameter_aclcheck and
pg_largeobject_aclcheck_snapshot) do not need tracking: pg_parameter_aclcheck
checks GUC parameters which are not dependency targets, and
pg_largeobject_aclcheck_snapshot is only called from inv_open() and
has_largeobject_privilege(), neither of which records dependencies.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/aclchk.c         | 7 +++++--
 src/backend/catalog/pg_depend.c      | 7 ++++++-
 src/include/catalog/aclcheck_track.h | 8 ++++++--
 3 files changed, 17 insertions(+), 5 deletions(-)
  64.1% src/backend/catalog/
  35.8% src/include/catalog/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 02c4489f0c4..fb51ea2e869 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -3899,7 +3899,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 	{
-		aclcheck_track_record(classid, objectid, roleid, mode);
+		aclcheck_track_record(classid, objectid, InvalidAttrNumber, roleid, mode);
 		return ACLCHECK_OK;
 	}
 	else
@@ -3934,7 +3934,10 @@ pg_attribute_aclcheck_ext(Oid table_oid, AttrNumber attnum,
 {
 	if (pg_attribute_aclmask_ext(table_oid, attnum, roleid, mode,
 								 ACLMASK_ANY, is_missing) != 0)
+	{
+		aclcheck_track_record(RelationRelationId, table_oid, attnum, roleid, mode);
 		return ACLCHECK_OK;
+	}
 	else
 		return ACLCHECK_NO_PRIV;
 }
@@ -4104,7 +4107,7 @@ pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 	{
-		aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
+		aclcheck_track_record(RelationRelationId, table_oid, InvalidAttrNumber, roleid, mode);
 		return ACLCHECK_OK;
 	}
 	else
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 912c92e8fef..88a27fdc802 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -773,7 +773,12 @@ recheckAcl(Oid classId, Oid objectId)
 		{
 			AclResult	aclresult;
 
-			if (classId == RelationRelationId)
+			if (acltable->entries[i].attnum != InvalidAttrNumber)
+				aclresult = pg_attribute_aclcheck(objectId,
+												  acltable->entries[i].attnum,
+												  acltable->entries[i].roleId,
+												  acltable->entries[i].mode);
+			else if (classId == RelationRelationId)
 				aclresult = pg_class_aclcheck(objectId,
 											  acltable->entries[i].roleId,
 											  acltable->entries[i].mode);
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
index d994cf7889b..4ac65e4de5c 100644
--- a/src/include/catalog/aclcheck_track.h
+++ b/src/include/catalog/aclcheck_track.h
@@ -30,6 +30,7 @@ typedef struct AclCheckEntry
 {
 	Oid			classId;
 	Oid			objectId;
+	AttrNumber	attnum;
 	Oid			roleId;
 	AclMode		mode;
 	uint64		inval_count;
@@ -50,11 +51,13 @@ extern void FreeTrackAclTable(TrackAclTable *acltable);
 /*
  * Record an aclcheck for later revalidation.
  *
- * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Called from object_aclcheck_ext(), pg_class_aclcheck_ext(), and
+ * pg_attribute_aclcheck_ext().
  * Only records when inside an utility statement.
  */
 static inline void
-aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+aclcheck_track_record(Oid classId, Oid objectId, AttrNumber attnum,
+					  Oid roleId, AclMode mode)
 {
 	TrackAclTable *acltable = CurrentTrackAclTable;
 	AclCheckEntry *entry;
@@ -72,6 +75,7 @@ aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
 	entry = &acltable->entries[acltable->count++];
 	entry->classId = classId;
 	entry->objectId = objectId;
+	entry->attnum = attnum;
 	entry->roleId = roleId;
 	entry->mode = mode;
 	entry->inval_count = SharedInvalidMessageCounter;
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-16 10:09                                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-16 19:14                                                                                             ` Jeff Davis <pgsql@j-davis.com>
  2026-06-17 05:44                                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2026-06-16 19:14 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Tue, 2026-06-16 at 10:09 +0000, Bertrand Drouvot wrote:
> 0002: fixes it by moving aclcheck_track_record() to after the
> permission check
> succeeds in object_aclcheck_ext() and pg_class_aclcheck_ext().
> Indeed, there is
> no need to track failed permission checks.

IIUC, this is necessary for correctness. If an ACL failure doesn't
cause a transaction abort, then there's a danger that we cause the
transaction to fail that should have succeeded.

So the ACL tracking needs to be precise: we can't track an ACL check
unless a failure always causes transaction abort; and we must track an
ACL check if it would cause a transaction abort. Right?

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-16 10:09                                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 19:14                                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-17 05:44                                                                                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-18 23:21                                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  0 siblings, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-17 05:44 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Tue, Jun 16, 2026 at 12:14:12PM -0700, Jeff Davis wrote:
> On Tue, 2026-06-16 at 10:09 +0000, Bertrand Drouvot wrote:
> > 0002: fixes it by moving aclcheck_track_record() to after the
> > permission check
> > succeeds in object_aclcheck_ext() and pg_class_aclcheck_ext().
> > Indeed, there is
> > no need to track failed permission checks.
> 
> IIUC, this is necessary for correctness. If an ACL failure doesn't
> cause a transaction abort, then there's a danger that we cause the
> transaction to fail that should have succeeded.

Exactly, because we'd recheck an "harmless" failed ACL check and then produce
an error.

> So the ACL tracking needs to be precise: we can't track an ACL check
> unless a failure always causes transaction abort; and we must track an
> ACL check if it would cause a transaction abort. Right?

I would say: we just need to track (and recheck) ACL checks that succeeded.

I think that there is no reason to recheck (and so to record) a failed ACL as what
we are dealing with here is the TOCTOU window. Re-checking a failed ACL check would
handle cases when a GRANT has been given during the TOCTOU window which is not
useful (for our protection goal) compared to re-checking a REVOKE during the
TOCTOU window (as the latter would record a dependency on an object we don't have
permission on).

Doing so, as proposed in 0002, allows us to fix the "re-check a harmless failed
ACL bug" (demonstrated by the added test) and still protect us for REVOKE during
the TOCTOU window.

Thoughts?

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-16 10:09                                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 19:14                                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-17 05:44                                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-18 23:21                                                                                                 ` Jeff Davis <pgsql@j-davis.com>
  2026-06-19 02:13                                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-19 13:28                                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 2 replies; 93+ messages in thread

From: Jeff Davis @ 2026-06-18 23:21 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Wed, 2026-06-17 at 05:44 +0000, Bertrand Drouvot wrote:
> > IIUC, this is necessary for correctness. If an ACL failure doesn't
> > cause a transaction abort, then there's a danger that we cause the
> > transaction to fail that should have succeeded.
> 
> Exactly, because we'd recheck an "harmless" failed ACL check and then
> produce
> an error.
> 
> > So the ACL tracking needs to be precise: we can't track an ACL
> > check
> > unless a failure always causes transaction abort; and we must track
> > an
> > ACL check if it would cause a transaction abort. Right?
> 
> I would say: we just need to track (and recheck) ACL checks that
> succeeded.

IIUC, we cannot have false positives (tracking ACL checks that wouldn't
have caused an abort) nor can we have false negatives (missing an ACL
check that could cause an abort).

It's hard for me to convince myself that we got all the cases right;
and if we have, that they won't be broken in the future.

For instance, I just realized that something else I'm working on is
related:

https://www.postgresql.org/message-id/5c629d2455946ad2fde3c184f64ea2c323ef2133.camel@j-davis.com

It does an ACL check inside a subtransaction, where the parent
transaction is a DDL statement. It happens to be a DROP statement, so
it's not recording new dependencies, so I don't think it breaks your
tracking mechanism, but it's too close for comfort.

We could keep the transaction ID in the tracking record, and ignore
entries from an aborted subxact. But it's getting fairly complex and
delicate.

Thoughts?

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-16 10:09                                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 19:14                                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-17 05:44                                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-18 23:21                                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-19 02:13                                                                                                   ` Jeff Davis <pgsql@j-davis.com>
  2026-06-19 13:36                                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Jeff Davis @ 2026-06-19 02:13 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

On Thu, 2026-06-18 at 16:21 -0700, Jeff Davis wrote:
> IIUC, we cannot have false positives (tracking ACL checks that
> wouldn't
> have caused an abort) nor can we have false negatives (missing an ACL
> check that could cause an abort).

Idea: what if we check for changes in ACLs on the object, rather than
whether it passes the check or not?

Then, if track an ACL check that wouldn't actually cause a failure,
then it still might be acceptable to throw an error if the ACL changes.
Still some details to sort out, so this is just an idea.

Regards,
	Jeff Davis






^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-16 10:09                                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 19:14                                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-17 05:44                                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-18 23:21                                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-19 02:13                                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-19 13:36                                                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-19 13:36 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jun 18, 2026 at 07:13:38PM -0700, Jeff Davis wrote:
> On Thu, 2026-06-18 at 16:21 -0700, Jeff Davis wrote:
> > IIUC, we cannot have false positives (tracking ACL checks that
> > wouldn't
> > have caused an abort) nor can we have false negatives (missing an ACL
> > check that could cause an abort).
> 
> Idea: what if we check for changes in ACLs on the object, rather than
> whether it passes the check or not?
> 
> Then, if track an ACL check that wouldn't actually cause a failure,
> then it still might be acceptable to throw an error if the ACL changes.
> Still some details to sort out, so this is just an idea.

Yeah, I think I do prefer this idea. As you say, that could cause an error even
if the ACL change does not REVOKE anything on this object (say the ACL change is
a GRANT), but that should be rare in practice and probably much simpler to reason
about that way.

But I don't think tracking ACL changes would be enough though. I think we would
also need to track ROLE changes.

So what about?

- Save a copy of the object's ACL and compare at recheck time: If not the same,
then error out.
- Save the ROLE membership and compare at recheck time. If not the same, then
error out.

That way we cover both parts: the object's ACL and the ROLE membership.

That's just a high level idea, I can move forward and try to implement it.

Thoughts?

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-16 10:09                                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 19:14                                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-17 05:44                                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-18 23:21                                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
@ 2026-06-19 13:28                                                                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-25 11:10                                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-19 13:28 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Thu, Jun 18, 2026 at 04:21:33PM -0700, Jeff Davis wrote:
> On Wed, 2026-06-17 at 05:44 +0000, Bertrand Drouvot wrote:
> > > IIUC, this is necessary for correctness. If an ACL failure doesn't
> > > cause a transaction abort, then there's a danger that we cause the
> > > transaction to fail that should have succeeded.
> > 
> > Exactly, because we'd recheck an "harmless" failed ACL check and then
> > produce
> > an error.
> > 
> > > So the ACL tracking needs to be precise: we can't track an ACL
> > > check
> > > unless a failure always causes transaction abort; and we must track
> > > an
> > > ACL check if it would cause a transaction abort. Right?
> > 
> > I would say: we just need to track (and recheck) ACL checks that
> > succeeded.
> 
> IIUC, we cannot have false positives (tracking ACL checks that wouldn't
> have caused an abort) nor can we have false negatives (missing an ACL
> check that could cause an abort).

Right.

> It's hard for me to convince myself that we got all the cases right;
> and if we have, that they won't be broken in the future.
> 
> For instance, I just realized that something else I'm working on is
> related:
> 
> https://www.postgresql.org/message-id/5c629d2455946ad2fde3c184f64ea2c323ef2133.camel@j-davis.com
> 
> It does an ACL check inside a subtransaction, where the parent
> transaction is a DDL statement. It happens to be a DROP statement, so
> it's not recording new dependencies, so I don't think it breaks your
> tracking mechanism, but it's too close for comfort.

I see, I don't think we have this pattern currently but yeah we may have it
in the future (and our current tracking mechanism would probably fail in such a
case).

> We could keep the transaction ID in the tracking record, and ignore
> entries from an aborted subxact. But it's getting fairly complex and
> delicate.

Agreed. We could use RegisterSubXactCallback to save/restore the entry count on
subtransaction abort, but as you say it adds complexity.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 10:31                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-21 12:53                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2024-05-22 10:21                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-22 14:48                                   ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-19 17:02                                     ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-19 18:07                                       ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-20 21:12                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-21 16:55                                           ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-05-21 17:17                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2025-05-22 12:15                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-05-22 13:40                                                 ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-02 14:02                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-06-03 17:27                                                     ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2025-06-06 05:37                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2025-11-09 08:33                                                         ` Re: Avoid orphaned objects dependencies, take 3 Roman Eskin <r.eskin@arenadata.io>
  2026-04-15 18:36                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-04-28 11:17                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-13 20:20                                                               ` Re: Avoid orphaned objects dependencies, take 3 Robert Haas <robertmhaas@gmail.com>
  2026-05-18 12:14                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-26 18:00                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-05-26 20:18                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-05-27 15:53                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Heikki Linnakangas <hlinnaka@iki.fi>
  2026-06-01 09:21                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-04 17:03                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-05 13:09                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-08 21:55                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-09 06:47                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-09 21:44                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-10 12:31                                                                                     ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-10 15:16                                                                                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 01:19                                                                                         ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-16 10:09                                                                                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-16 19:14                                                                                             ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-17 05:44                                                                                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2026-06-18 23:21                                                                                                 ` Re: Avoid orphaned objects dependencies, take 3 Jeff Davis <pgsql@j-davis.com>
  2026-06-19 13:28                                                                                                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2026-06-25 11:10                                                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2026-06-25 11:10 UTC (permalink / raw)
  To: Jeff Davis <pgsql@j-davis.com>; +Cc: Heikki Linnakangas <hlinnaka@iki.fi>; Robert Haas <robertmhaas@gmail.com>; Roman Eskin <r.eskin@arenadata.io>; Michael Paquier <michael@paquier.xyz>; Alexander Lakhin <exclusion@gmail.com>; pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>

Hi,

On Fri, Jun 19, 2026 at 01:28:21PM +0000, Bertrand Drouvot wrote:
> Hi,
> 
> On Thu, Jun 18, 2026 at 04:21:33PM -0700, Jeff Davis wrote:
> 
> > We could keep the transaction ID in the tracking record, and ignore
> > entries from an aborted subxact. But it's getting fairly complex and
> > delicate.

As discussed off-list, let's move forward with this proposal (as the save a copy
of the object's ACL + ROLE membership mentioned in [1] would be more complex and
fragile).

So PFA the new version doing so. It's the same patch series as the previous one
except that it adds:

0004: Discard ACL tracking entries from aborted subtransactions

It stores SubTransactionId in each AclCheckEntry at recording time.
On subtransaction abort, AtEOSubXact_AclTrack() discards entries whose subxid
is >= the aborting subtransaction's ID.

The code is pretty simple but I suspect that adding a test would probably need to
create a brand new module (say test_acltrack) with C code forcing
recordDependencyOn() and BeginInternalSubTransaction()) and I'm not sure it's
worth it. Indeed, I think the test would need to do things similar to what you
shared in [2].

The patch is split to ease the review but should probably be merged as a single
patch.

[1]: https://postgr.es/m/ajVF7YWf%2Bpxs4cOf%40bdtpg
[2]: https://postgr.es/m/5c629d2455946ad2fde3c184f64ea2c323ef2133.camel@j-davis.com

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v28-0001-Recheck-permissions-after-lock-acquisition-in-de.patch (28.9K, ../../aj0MwjV1RKV8FvCG@bdtpg/2-v28-0001-Recheck-permissions-after-lock-acquisition-in-de.patch)
  download | inline diff:
From 7821e87701c95321a5cb807e29217dcfaf4adee4 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Sat, 30 May 2026 14:35:40 +0000
Subject: [PATCH v28 1/5] Recheck permissions after lock acquisition in
 dependency recording

After dependencyLockAndCheckObject() acquires a lock on a referenced object
(which may have blocked on a concurrent DROP), re-verify any permission check
that was done earlier in the statement. This closes the TOCTOU window where a
REVOKE could land between the original permission check and the dependency
recording.

The approach: record SharedInvalidMessageCounter at the time of the original
aclcheck. After acquiring the lock and verifying the object still exists,
compare the saved counter with the current value. If it changed (meaning
catalog invalidations arrived since the original check), re-verify the
permission. Since the OID is fixed (no name re-resolution), a failure is
definitive and no retry loop is needed.

Each ProcessUtility() call allocates a TrackAclTable in CurrentMemoryContext
and saves the previous one in a local variable. A PG_TRY/PG_FINALLY block
ensures that the table is freed and the previous pointer restored on both
normal return and error. This forms an implicit stack: each nesting level
tracks only its own ACL checks, and the outer level's entries remain
undisturbed. No dedicated memory context or AbortTransaction cleanup is needed.

Recording is gated by checking CurrentTrackAclTable != NULL, so DML and queries
pay only a single pointer test.

Alternatives considered:

- To avoid allocating memory for each statement, keep the array in
TopMemoryContext and never free it (only resetting the count). But that left the
high-water mark allocated for the lifetime of the backend.

- Passing privilege info (roleId, mode) as extra arguments through the
  dependency recording APIs (recordDependencyOn, recordMultipleDependencies,
  etc.) was discarded because expression-based dependencies
  (recordDependencyOnExpr, find_expr_references_walker) discover objects by
  walking expression trees: the caller never sees individual objects and cannot
  attach privilege info to them.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/aclchk.c                  |  32 ++++
 src/backend/catalog/pg_depend.c               | 104 ++++++++++++-
 src/backend/tcop/utility.c                    |  41 +++--
 src/include/catalog/aclcheck_track.h          |  80 ++++++++++
 .../expected/ddl-dependency-locking.out       |  64 +++++++-
 .../specs/ddl-dependency-locking.spec         | 140 ++++++++++++++++++
 src/tools/pgindent/typedefs.list              |   2 +
 7 files changed, 441 insertions(+), 22 deletions(-)
  20.0% src/backend/catalog/
   6.7% src/backend/tcop/
  11.7% src/include/catalog/
  20.5% src/test/isolation/expected/
  40.7% src/test/isolation/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 007ede997c5..ab19db9d789 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -44,6 +44,7 @@
 #include "access/sysattr.h"
 #include "access/tableam.h"
 #include "access/xact.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/binary_upgrade.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
@@ -84,6 +85,10 @@
 #include "utils/rel.h"
 #include "utils/syscache.h"
 
+#define ACLCHECK_TRACK_INITIAL_SIZE 64
+
+TrackAclTable *CurrentTrackAclTable = NULL;
+
 /*
  * Internal format used by ALTER DEFAULT PRIVILEGES.
  */
@@ -3891,6 +3896,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
+	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 		return ACLCHECK_OK;
@@ -4093,6 +4099,7 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
+	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 		return ACLCHECK_OK;
@@ -5036,3 +5043,28 @@ RemoveRoleFromInitPriv(Oid roleid, Oid classid, Oid objid, int32 objsubid)
 
 	table_close(rel, RowExclusiveLock);
 }
+
+/*
+ * Allocate a new tracking table in CurrentMemoryContext.
+ */
+TrackAclTable *
+CreateTrackAclTable(void)
+{
+	TrackAclTable *acltable = (TrackAclTable *) palloc(sizeof(TrackAclTable));
+
+	acltable->entries = (AclCheckEntry *)
+		palloc(ACLCHECK_TRACK_INITIAL_SIZE * sizeof(AclCheckEntry));
+	acltable->max = ACLCHECK_TRACK_INITIAL_SIZE;
+	acltable->count = 0;
+	return acltable;
+}
+
+/*
+ * Free a tracking table.
+ */
+void
+FreeTrackAclTable(TrackAclTable *acltable)
+{
+	pfree(acltable->entries);
+	pfree(acltable);
+}
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 9a7a401aced..912c92e8fef 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -17,6 +17,7 @@
 #include "access/genam.h"
 #include "access/htup_details.h"
 #include "access/table.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/catalog.h"
 #include "catalog/dependency.h"
 #include "catalog/indexing.h"
@@ -29,6 +30,8 @@
 #include "miscadmin.h"
 #include "storage/lmgr.h"
 #include "storage/lock.h"
+#include "storage/sinval.h"
+#include "utils/acl.h"
 #include "utils/fmgroids.h"
 #include "utils/lsyscache.h"
 #include "utils/rel.h"
@@ -38,6 +41,7 @@
 
 static bool isObjectPinned(const ObjectAddress *object);
 static void dependencyLockAndCheckObject(Oid classId, Oid objectId);
+static void recheckAcl(Oid classId, Oid objectId);
 
 
 /*
@@ -732,12 +736,76 @@ isObjectPinned(const ObjectAddress *object)
 }
 
 
+/*
+ * recheckAcl()
+ *
+ * Re-verify all tracked permission checks on the given object.
+ *
+ * Called after acquiring the lock and verifying the object still exists.
+ * If permission checks were tracked for this object and catalog
+ * invalidations arrived since the original checks, re-verify them all.
+ * This closes the TOCTOU window where a REVOKE could land between the
+ * original permission check and the dependency recording.
+ *
+ * Multiple checks may have been done on the same object with different
+ * modes or roles, so we iterate through all matching entries.
+ *
+ * Since we don't re-resolve names (the OID is fixed), there is no need for
+ * a retry loop here. If a recheck fails, it's a definitive failure.
+ *
+ * The linear scan over the tracking array is O(n) in the number of tracked
+ * entries, but that's fine since a typical DDL statement tracks only a few
+ * objects.
+ */
+static void
+recheckAcl(Oid classId, Oid objectId)
+{
+	TrackAclTable *acltable = CurrentTrackAclTable;
+
+	if (acltable == NULL)
+		return;
+
+	for (int i = acltable->count - 1; i >= 0; i--)
+	{
+		if (acltable->entries[i].classId == classId &&
+			acltable->entries[i].objectId == objectId &&
+			acltable->entries[i].inval_count != SharedInvalidMessageCounter)
+		{
+			AclResult	aclresult;
+
+			if (classId == RelationRelationId)
+				aclresult = pg_class_aclcheck(objectId,
+											  acltable->entries[i].roleId,
+											  acltable->entries[i].mode);
+			else
+				aclresult = object_aclcheck(classId, objectId,
+											acltable->entries[i].roleId,
+											acltable->entries[i].mode);
+
+			if (aclresult != ACLCHECK_OK)
+			{
+				ObjectAddress object;
+
+				object.classId = classId;
+				object.objectId = objectId;
+				object.objectSubId = 0;
+				ereport(ERROR,
+						(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
+						 errmsg("permission denied for %s",
+								getObjectDescription(&object, false))));
+			}
+		}
+	}
+}
+
+
 /*
  * dependencyLockAndCheckObject
  *
- * Lock the object that we are about to record a dependency on.  After it's
- * locked, verify that it hasn't been dropped while we weren't looking.  If it
- * has been dropped, throw an an error.
+ * Lock the object that we are about to record a dependency on. After it's
+ * locked, verify that it hasn't been dropped while we weren't looking. If it
+ * has been dropped, throw an error. Then re-verify any tracked permission
+ * check to close the TOCTOU window.
  *
  * If the caller already holds a lock that conflicts with DROP
  * (AccessShareLock or stronger), this does nothing.  Callers should acquire
@@ -773,7 +841,11 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 						   0);
 
 		if (LockHeldByMe(&tag, AccessShareLock, true))
+		{
+			/* Recheck ACL */
+			recheckAcl(classId, objectId);
 			return;
+		}
 
 		/* Assume we should lock the whole object not a sub-object */
 		LockDatabaseObject(classId, objectId, 0, AccessShareLock);
@@ -786,7 +858,11 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		if (cache != SYSCACHEID_INVALID)
 		{
 			if (SearchSysCacheExists1(cache, ObjectIdGetDatum(objectId)))
+			{
+				/* Recheck ACL */
+				recheckAcl(classId, objectId);
 				return;
+			}
 		}
 
 		/*
@@ -814,6 +890,9 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 
 		systable_endscan(scan);
 		table_close(rel, AccessShareLock);
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 	else
 	{
@@ -834,14 +913,23 @@ dependencyLockAndCheckObject(Oid classId, Oid objectId)
 		Assert(!IsSharedRelation(objectId));
 
 		if (CheckRelationOidLockedByMe(objectId, AccessShareLock, true))
+		{
+			/* Recheck ACL */
+			recheckAcl(classId, objectId);
 			return;
+		}
+
+		/* Acquire lock */
 		LockRelationOid(objectId, AccessShareLock);
 
-		if (SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
-			return;
-		ereport(ERROR,
-				(errcode(ERRCODE_UNDEFINED_OBJECT),
-				 errmsg("referenced relation was concurrently dropped")));
+		/* Check that the object still exists */
+		if (!SearchSysCacheExists1(RELOID, ObjectIdGetDatum(objectId)))
+			ereport(ERROR,
+					(errcode(ERRCODE_UNDEFINED_OBJECT),
+					 errmsg("referenced relation was concurrently dropped")));
+
+		/* Recheck ACL */
+		recheckAcl(classId, objectId);
 	}
 }
 
diff --git a/src/backend/tcop/utility.c b/src/backend/tcop/utility.c
index 73a56f1df1d..1fad5d9a78d 100644
--- a/src/backend/tcop/utility.c
+++ b/src/backend/tcop/utility.c
@@ -20,6 +20,7 @@
 #include "access/twophase.h"
 #include "access/xact.h"
 #include "access/xlog.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_authid.h"
 #include "catalog/pg_inherits.h"
@@ -510,24 +511,38 @@ ProcessUtility(PlannedStmt *pstmt,
 			   DestReceiver *dest,
 			   QueryCompletion *qc)
 {
+	TrackAclTable *prevTrackAclTable = CurrentTrackAclTable;
+
 	Assert(IsA(pstmt, PlannedStmt));
 	Assert(pstmt->commandType == CMD_UTILITY);
 	Assert(queryString != NULL);	/* required as of 8.4 */
 	Assert(qc == NULL || qc->commandTag == CMDTAG_UNKNOWN);
 
-	/*
-	 * We provide a function hook variable that lets loadable plugins get
-	 * control when ProcessUtility is called.  Such a plugin would normally
-	 * call standard_ProcessUtility().
-	 */
-	if (ProcessUtility_hook)
-		(*ProcessUtility_hook) (pstmt, queryString, readOnlyTree,
-								context, params, queryEnv,
-								dest, qc);
-	else
-		standard_ProcessUtility(pstmt, queryString, readOnlyTree,
-								context, params, queryEnv,
-								dest, qc);
+	/* Allocate a fresh acl tracking table for this utility statement. */
+	CurrentTrackAclTable = CreateTrackAclTable();
+
+	PG_TRY();
+	{
+		/*
+		 * We provide a function hook variable that lets loadable plugins get
+		 * control when ProcessUtility is called.  Such a plugin would
+		 * normally call standard_ProcessUtility().
+		 */
+		if (ProcessUtility_hook)
+			(*ProcessUtility_hook) (pstmt, queryString, readOnlyTree,
+									context, params, queryEnv,
+									dest, qc);
+		else
+			standard_ProcessUtility(pstmt, queryString, readOnlyTree,
+									context, params, queryEnv,
+									dest, qc);
+	}
+	PG_FINALLY();
+	{
+		FreeTrackAclTable(CurrentTrackAclTable);
+		CurrentTrackAclTable = prevTrackAclTable;
+	}
+	PG_END_TRY();
 }
 
 /*
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
new file mode 100644
index 00000000000..d994cf7889b
--- /dev/null
+++ b/src/include/catalog/aclcheck_track.h
@@ -0,0 +1,80 @@
+/*-------------------------------------------------------------------------
+ *
+ * aclcheck_track.h
+ *	  Track permission checks for revalidation after lock acquisition
+ *	  in dependencyLockAndCheckObject().
+ *
+ * DDL may perform ACL checks on referenced objects without first holding a lock
+ * on them. In that case, the lock is acquired much later, when recording
+ * dependencies.
+ * Track the ACL checks, so that we can re-check them after acquiring the
+ * lock while recording dependencies.
+ *
+ * XXX: consider refactoring so that we perform the name lookup, acquire the
+ * lock, and check ACLs all in unison, like RangeVarGetRelidExtended().
+ *
+ * Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group
+ * Portions Copyright (c) 1994, Regents of the University of California
+ *
+ * src/include/catalog/aclcheck_track.h
+ *
+ *-------------------------------------------------------------------------
+ */
+#ifndef ACLCHECK_TRACK_H
+#define ACLCHECK_TRACK_H
+
+#include "storage/sinval.h"
+#include "utils/acl.h"
+
+typedef struct AclCheckEntry
+{
+	Oid			classId;
+	Oid			objectId;
+	Oid			roleId;
+	AclMode		mode;
+	uint64		inval_count;
+} AclCheckEntry;
+
+typedef struct TrackAclTable
+{
+	AclCheckEntry *entries;
+	int			count;
+	int			max;
+} TrackAclTable;
+
+extern TrackAclTable *CurrentTrackAclTable;
+
+extern TrackAclTable *CreateTrackAclTable(void);
+extern void FreeTrackAclTable(TrackAclTable *acltable);
+
+/*
+ * Record an aclcheck for later revalidation.
+ *
+ * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Only records when inside an utility statement.
+ */
+static inline void
+aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+{
+	TrackAclTable *acltable = CurrentTrackAclTable;
+	AclCheckEntry *entry;
+
+	if (acltable == NULL)
+		return;
+
+	if (acltable->count >= acltable->max)
+	{
+		acltable->max *= 2;
+		acltable->entries = (AclCheckEntry *)
+			repalloc(acltable->entries, acltable->max * sizeof(AclCheckEntry));
+	}
+
+	entry = &acltable->entries[acltable->count++];
+	entry->classId = classId;
+	entry->objectId = objectId;
+	entry->roleId = roleId;
+	entry->mode = mode;
+	entry->inval_count = SharedInvalidMessageCounter;
+}
+
+#endif							/* ACLCHECK_TRACK_H */
diff --git a/src/test/isolation/expected/ddl-dependency-locking.out b/src/test/isolation/expected/ddl-dependency-locking.out
index 636de281022..77cc7489170 100644
--- a/src/test/isolation/expected/ddl-dependency-locking.out
+++ b/src/test/isolation/expected/ddl-dependency-locking.out
@@ -1,4 +1,4 @@
-Parsed test spec with 2 sessions
+Parsed test spec with 3 sessions
 
 starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
 step s1_begin: BEGIN;
@@ -135,3 +135,65 @@ step s2_drop_role: DROP ROLE regress_dependency; <waiting ...>
 step s1_commit: COMMIT;
 step s2_drop_role: <... completed>
 ERROR:  role "regress_dependency" cannot be dropped because some objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_as_role_user s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_as_role_user: SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_as_role_user: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_wrapper
+
+starting permutation: s2_begin s2_drop_fdw_spi_func s1_create_server_spi_func s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_spi_func: DROP FOREIGN DATA WRAPPER fdw_spi_func RESTRICT;
+step s1_create_server_spi_func: SET ROLE role_user; CREATE SERVER srv_spi_func FOREIGN DATA WRAPPER fdw_spi_func; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_spi_func: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_spi_func
+
+starting permutation: s2_begin s2_drop_fdw_spi_rollback s1_create_server_spi_rollback s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_spi_rollback: DROP FOREIGN DATA WRAPPER fdw_spi_rollback RESTRICT;
+step s1_create_server_spi_rollback: SET ROLE role_user; CREATE SERVER srv_spi_rollback FOREIGN DATA WRAPPER fdw_spi_rollback; RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_spi_rollback: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_spi_rollback
+
+starting permutation: s2_begin s2_drop_fdw_trigger s1_insert_trigger_ddl s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_trigger: DROP FOREIGN DATA WRAPPER fdw_trigger RESTRICT;
+step s1_insert_trigger_ddl: SET ROLE role_user; INSERT INTO trigger_tbl VALUES (1); RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_insert_trigger_ddl: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_trigger
+
+starting permutation: s2_begin s2_drop_fdw_trigger_spi s1_insert_trigger_spi_ddl s3_revoke_role s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_trigger_spi: DROP FOREIGN DATA WRAPPER fdw_trigger_spi_func RESTRICT;
+step s1_insert_trigger_spi_ddl: SET ROLE role_user; INSERT INTO trigger_spi_tbl VALUES (1); RESET ROLE; <waiting ...>
+step s3_revoke_role: REVOKE role_fdw FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_insert_trigger_spi_ddl: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_trigger_spi_func
+
+starting permutation: s2_begin s2_drop_fdw_inner s1_create_server_nested_toctou s3_revoke_both_roles s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_inner: DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT;
+step s1_create_server_nested_toctou: SET ROLE role_user; CREATE SERVER srv_outer FOREIGN DATA WRAPPER fdw_outer; RESET ROLE; <waiting ...>
+step s3_revoke_both_roles: REVOKE role_fdw, role_fdw_inner FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_nested_toctou: <... completed>
+ERROR:  permission denied for foreign-data wrapper fdw_inner
+
+starting permutation: s2_begin s2_drop_fdw_inner s1_create_server_nested_rollback s3_revoke_role_inner s2_rollback
+step s2_begin: BEGIN;
+step s2_drop_fdw_inner: DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT;
+step s1_create_server_nested_rollback: SET ROLE role_user; CREATE SERVER srv_outer_rollback FOREIGN DATA WRAPPER fdw_outer_rollback; RESET ROLE; <waiting ...>
+step s3_revoke_role_inner: REVOKE role_fdw_inner FROM role_user;
+step s2_rollback: ROLLBACK;
+step s1_create_server_nested_rollback: <... completed>
diff --git a/src/test/isolation/specs/ddl-dependency-locking.spec b/src/test/isolation/specs/ddl-dependency-locking.spec
index de5bd88d35e..72aa97c6dfd 100644
--- a/src/test/isolation/specs/ddl-dependency-locking.spec
+++ b/src/test/isolation/specs/ddl-dependency-locking.spec
@@ -11,7 +11,71 @@ setup
 	CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
 	CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+	CREATE ROLE role_fdw;
+	CREATE ROLE role_user LOGIN;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_wrapper TO role_fdw;
+	GRANT role_fdw TO role_user;
 	CREATE ROLE regress_dependency;
+	CREATE FUNCTION spi_func(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE TEMP TABLE IF NOT EXISTS validator_side_effect(x int)'; END; $$;
+	CREATE FUNCTION spi_func_rollback(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    BEGIN
+	      EXECUTE 'CREATE TEMP TABLE validator_will_rollback(x int)';
+	      RAISE EXCEPTION 'force rollback';
+	    EXCEPTION WHEN OTHERS THEN
+	      NULL;
+	    END;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_spi_func VALIDATOR spi_func;
+	CREATE FOREIGN DATA WRAPPER fdw_spi_rollback VALIDATOR spi_func_rollback;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_spi_func TO role_fdw;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_spi_rollback TO role_fdw;
+	CREATE FOREIGN DATA WRAPPER fdw_trigger;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_trigger TO role_fdw;
+	CREATE FUNCTION trg_create_server() RETURNS trigger
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE SERVER srv_from_trigger FOREIGN DATA WRAPPER fdw_trigger'; RETURN NEW; END; $$;
+	CREATE TABLE trigger_tbl(a int);
+	GRANT INSERT ON trigger_tbl TO role_user;
+	CREATE TRIGGER trg BEFORE INSERT ON trigger_tbl
+	  FOR EACH ROW EXECUTE FUNCTION trg_create_server();
+	CREATE FOREIGN DATA WRAPPER fdw_trigger_spi_func VALIDATOR spi_func;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_trigger_spi_func TO role_fdw;
+	CREATE FUNCTION trg_create_server_spi_func() RETURNS trigger
+	  LANGUAGE plpgsql AS $$ BEGIN EXECUTE 'CREATE SERVER srv_from_trigger_spi FOREIGN DATA WRAPPER fdw_trigger_spi_func'; RETURN NEW; END; $$;
+	CREATE TABLE trigger_spi_tbl(a int);
+	GRANT INSERT ON trigger_spi_tbl TO role_user;
+	CREATE TRIGGER trg BEFORE INSERT ON trigger_spi_tbl
+	  FOR EACH ROW EXECUTE FUNCTION trg_create_server_spi_func();
+	CREATE FOREIGN DATA WRAPPER fdw_inner;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_inner TO role_fdw;
+	CREATE FUNCTION spi_func_create_server(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    IF $2 = 'pg_catalog.pg_foreign_server'::regclass::oid THEN
+	      EXECUTE 'CREATE SERVER srv_nested_inner FOREIGN DATA WRAPPER fdw_inner';
+	    END IF;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_outer VALIDATOR spi_func_create_server;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_outer TO role_fdw;
+	CREATE ROLE role_fdw_inner;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_inner TO role_fdw_inner;
+	GRANT role_fdw_inner TO role_user;
+	CREATE FUNCTION spi_func_create_server_rollback(text[], oid) RETURNS void
+	  LANGUAGE plpgsql AS $$
+	  BEGIN
+	    IF $2 = 'pg_catalog.pg_foreign_server'::regclass::oid THEN
+	      BEGIN
+	        EXECUTE 'CREATE SERVER srv_nested_rollback FOREIGN DATA WRAPPER fdw_inner';
+	        RAISE EXCEPTION 'force rollback';
+	      EXCEPTION WHEN OTHERS THEN
+	        NULL;
+	      END;
+	    END IF;
+	  END; $$;
+	CREATE FOREIGN DATA WRAPPER fdw_outer_rollback VALIDATOR spi_func_create_server_rollback;
+	GRANT USAGE ON FOREIGN DATA WRAPPER fdw_outer_rollback TO role_fdw;
 }
 
 teardown
@@ -24,7 +88,19 @@ teardown
 	DROP FUNCTION IF EXISTS alterschema.falter();
 	DROP DOMAIN IF EXISTS idid;
 	DROP SERVER IF EXISTS srv_fdw_wrapper;
+	DROP SERVER IF EXISTS srv_role_revoked;
+	DROP SERVER IF EXISTS srv_spi_func;
+	DROP SERVER IF EXISTS srv_spi_rollback;
+	DROP SERVER IF EXISTS srv_from_trigger;
+	DROP SERVER IF EXISTS srv_from_trigger_spi;
+	DROP SERVER IF EXISTS srv_from_spi;
+	DROP SERVER IF EXISTS srv_nested_inner;
+	DROP SERVER IF EXISTS srv_nested_rollback;
+	DROP SERVER IF EXISTS srv_outer;
+	DROP SERVER IF EXISTS srv_outer_rollback;
 	DROP TABLE IF EXISTS tabtype;
+	DROP TABLE IF EXISTS trigger_tbl;
+	DROP TABLE IF EXISTS trigger_spi_tbl;
 	DROP SCHEMA IF EXISTS testschema;
 	DROP SCHEMA IF EXISTS alterschema;
 	DROP TYPE IF EXISTS public.foo;
@@ -32,6 +108,22 @@ teardown
 	DROP DOMAIN IF EXISTS id;
 	DROP FUNCTION IF EXISTS f();
 	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_spi_func;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_spi_rollback;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_trigger;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_trigger_spi_func;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_inner;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_outer;
+	DROP FOREIGN DATA WRAPPER IF EXISTS fdw_outer_rollback;
+	DROP FUNCTION IF EXISTS spi_func(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_rollback(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_create_server(text[], oid);
+	DROP FUNCTION IF EXISTS spi_func_create_server_rollback(text[], oid);
+	DROP FUNCTION IF EXISTS trg_create_server();
+	DROP FUNCTION IF EXISTS trg_create_server_spi_func();
+	DROP ROLE IF EXISTS role_user;
+	DROP ROLE IF EXISTS role_fdw;
+	DROP ROLE IF EXISTS role_fdw_inner;
 	DROP ROLE regress_dependency;
 }
 
@@ -47,6 +139,13 @@ step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alte
 step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
 step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
 step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_create_server_as_role_user" { SET ROLE role_user; CREATE SERVER srv_role_revoked FOREIGN DATA WRAPPER fdw_wrapper; RESET ROLE; }
+step "s1_create_server_spi_func" { SET ROLE role_user; CREATE SERVER srv_spi_func FOREIGN DATA WRAPPER fdw_spi_func; RESET ROLE; }
+step "s1_create_server_spi_rollback" { SET ROLE role_user; CREATE SERVER srv_spi_rollback FOREIGN DATA WRAPPER fdw_spi_rollback; RESET ROLE; }
+step "s1_insert_trigger_ddl" { SET ROLE role_user; INSERT INTO trigger_tbl VALUES (1); RESET ROLE; }
+step "s1_insert_trigger_spi_ddl" { SET ROLE role_user; INSERT INTO trigger_spi_tbl VALUES (1); RESET ROLE; }
+step "s1_create_server_nested_toctou" { SET ROLE role_user; CREATE SERVER srv_outer FOREIGN DATA WRAPPER fdw_outer; RESET ROLE; }
+step "s1_create_server_nested_rollback" { SET ROLE role_user; CREATE SERVER srv_outer_rollback FOREIGN DATA WRAPPER fdw_outer_rollback; RESET ROLE; }
 step "s1_commit" { COMMIT; }
 
 session "s2"
@@ -60,8 +159,20 @@ step "s2_drop_footab_type" { DROP TYPE public.footab; }
 step "s2_drop_function_f" { DROP FUNCTION f(); }
 step "s2_drop_domain_id" { DROP DOMAIN id; }
 step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_drop_fdw_spi_func" { DROP FOREIGN DATA WRAPPER fdw_spi_func RESTRICT; }
+step "s2_drop_fdw_spi_rollback" { DROP FOREIGN DATA WRAPPER fdw_spi_rollback RESTRICT; }
+step "s2_drop_fdw_trigger" { DROP FOREIGN DATA WRAPPER fdw_trigger RESTRICT; }
+step "s2_drop_fdw_trigger_spi" { DROP FOREIGN DATA WRAPPER fdw_trigger_spi_func RESTRICT; }
+step "s2_drop_fdw_inner" { DROP FOREIGN DATA WRAPPER fdw_inner RESTRICT; }
 step "s2_drop_role" { DROP ROLE regress_dependency; }
 step "s2_commit" { COMMIT; }
+step "s2_rollback" { ROLLBACK; }
+
+session "s3"
+
+step "s3_revoke_role" { REVOKE role_fdw FROM role_user; }
+step "s3_revoke_role_inner" { REVOKE role_fdw_inner FROM role_user; }
+step "s3_revoke_both_roles" { REVOKE role_fdw, role_fdw_inner FROM role_user; }
 
 # create function - drop schema
 permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
@@ -102,3 +213,32 @@ permutation "s1_begin" "s1_alter_function_owner" "s2_drop_role" "s1_commit"
 # <OID> was concurrently dropped", contains an OID that is not stable.
 #
 # permutation "s2_begin" "s2_drop_role" "s1_alter_function_owner" "s2_commit"
+
+# Role membership TOCTOU: permission via role revoked during lock wait.
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_as_role_user" "s3_revoke_role" "s2_rollback"
+
+# Role membership TOCTOU with SPI DDL in FDW validator.
+permutation "s2_begin" "s2_drop_fdw_spi_func" "s1_create_server_spi_func" "s3_revoke_role" "s2_rollback"
+
+# Same as above but the validator's SPI DDL fails and rolls back its
+# subtransaction.
+permutation "s2_begin" "s2_drop_fdw_spi_rollback" "s1_create_server_spi_rollback" "s3_revoke_role" "s2_rollback"
+
+# Role membership TOCTOU with DDL triggered from DML: a trigger function does
+# DDL via SPI during INSERT.
+permutation "s2_begin" "s2_drop_fdw_trigger" "s1_insert_trigger_ddl" "s3_revoke_role" "s2_rollback"
+
+# Same as above but the DDL inside the trigger uses an FDW with a SPI validator,
+# combining trigger-initiated DDL with nested SPI.
+permutation "s2_begin" "s2_drop_fdw_trigger_spi" "s1_insert_trigger_spi_ddl" "s3_revoke_role" "s2_rollback"
+
+# TOCTOU on the nested SPI DDL itself: the validator creates a server using
+# fdw_inner, session 2 blocks that by dropping fdw_inner, and the REVOKE
+# removes access to fdw_inner.
+permutation "s2_begin" "s2_drop_fdw_inner" "s1_create_server_nested_toctou" "s3_revoke_both_roles" "s2_rollback"
+
+# Rolled-back nested DDL should not cause the outer to fail: the validator
+# tries to create a server using fdw_inner (via role_fdw_inner) but rolls back.
+# The REVOKE removes role_fdw_inner, but the outer CREATE SERVER only needs
+# role_fdw (for fdw_outer_rollback), so it should succeed.
+permutation "s2_begin" "s2_drop_fdw_inner" "s1_create_server_nested_rollback" "s3_revoke_role_inner" "s2_rollback"
diff --git a/src/tools/pgindent/typedefs.list b/src/tools/pgindent/typedefs.list
index c5db6ca6705..86512ad23ca 100644
--- a/src/tools/pgindent/typedefs.list
+++ b/src/tools/pgindent/typedefs.list
@@ -19,6 +19,7 @@ AbsoluteTime
 AccessMethodInfo
 AccessPriv
 Acl
+AclCheckEntry
 AclItem
 AclMaskHow
 AclMode
@@ -3224,6 +3225,7 @@ ToastedAttribute
 TocEntry
 TokenAuxData
 TokenizedAuthLine
+TrackAclTable
 TrackItem
 TransApplyAction
 TransInvalidationInfo
-- 
2.34.1

  [text/x-diff] v28-0002-Only-track-successful-ACL-checks-in-aclcheck_tra.patch (8.0K, ../../aj0MwjV1RKV8FvCG@bdtpg/3-v28-0002-Only-track-successful-ACL-checks-in-aclcheck_tra.patch)
  download | inline diff:
From 6e4b8c7c17d8fb7672611c94b4b876e92f13561d Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Tue, 16 Jun 2026 07:31:28 +0000
Subject: [PATCH v28 2/5] Only track successful ACL checks in
 aclcheck_track_record()

Previously, aclcheck_track_record() was called before the actual permission
check, so both successful and failed checks were recorded. This caused a
problem with column-level REFERENCES: checkFkeyPermissions() first tries
pg_class_aclcheck() (which fails for column-level grants), then falls through
to pg_attribute_aclcheck() (which succeeds). The tracked failed entry could
trigger a spurious 'permission denied' in recheckAcl() if catalog
invalidations arrived between the check and dependency recording.

Fix by moving aclcheck_track_record() to after the permission check succeeds
in object_aclcheck_ext() and pg_class_aclcheck_ext().

Add an injection point in checkFkeyPermissions() and a test that reproduces
the issue by injecting invalidations while the FK creation is paused after
the failed table-level check.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/aclchk.c                  |  8 ++-
 src/backend/commands/tablecmds.c              |  4 ++
 src/test/modules/injection_points/Makefile    |  3 +-
 .../expected/fk_column_ref.out                | 33 +++++++++++
 src/test/modules/injection_points/meson.build |  1 +
 .../injection_points/specs/fk_column_ref.spec | 56 +++++++++++++++++++
 6 files changed, 102 insertions(+), 3 deletions(-)
   8.0% src/backend/catalog/
   3.2% src/backend/commands/
  27.0% src/test/modules/injection_points/expected/
  58.9% src/test/modules/injection_points/specs/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index ab19db9d789..02c4489f0c4 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -3896,10 +3896,12 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 					Oid roleid, AclMode mode,
 					bool *is_missing)
 {
-	aclcheck_track_record(classid, objectid, roleid, mode);
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
+	{
+		aclcheck_track_record(classid, objectid, roleid, mode);
 		return ACLCHECK_OK;
+	}
 	else
 		return ACLCHECK_NO_PRIV;
 }
@@ -4099,10 +4101,12 @@ AclResult
 pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 					  AclMode mode, bool *is_missing)
 {
-	aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
+	{
+		aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
 		return ACLCHECK_OK;
+	}
 	else
 		return ACLCHECK_NO_PRIV;
 }
diff --git a/src/backend/commands/tablecmds.c b/src/backend/commands/tablecmds.c
index 265dcfe7fda..5aa3704fb5d 100644
--- a/src/backend/commands/tablecmds.c
+++ b/src/backend/commands/tablecmds.c
@@ -101,6 +101,7 @@
 #include "utils/acl.h"
 #include "utils/builtins.h"
 #include "utils/fmgroids.h"
+#include "utils/injection_point.h"
 #include "utils/inval.h"
 #include "utils/lsyscache.h"
 #include "utils/memutils.h"
@@ -13929,6 +13930,9 @@ checkFkeyPermissions(Relation rel, int16 *attnums, int natts)
 								  ACL_REFERENCES);
 	if (aclresult == ACLCHECK_OK)
 		return;
+
+	INJECTION_POINT("checkFkeyPermissions-after-table-acl-fail", NULL);
+
 	/* Else we must have REFERENCES on each column */
 	for (i = 0; i < natts; i++)
 	{
diff --git a/src/test/modules/injection_points/Makefile b/src/test/modules/injection_points/Makefile
index c01d2fb095c..2af9d045555 100644
--- a/src/test/modules/injection_points/Makefile
+++ b/src/test/modules/injection_points/Makefile
@@ -19,7 +19,8 @@ ISOLATION = basic \
 	    repack_temporal_multirange \
 	    repack_toast \
 	    syscache-update-pruned \
-	    heap_lock_update
+	    heap_lock_update \
+	    fk_column_ref
 
 # some isolation tests require wal_level=replica
 ISOLATION_OPTS = --temp-config $(top_srcdir)/src/test/modules/injection_points/extra.conf
diff --git a/src/test/modules/injection_points/expected/fk_column_ref.out b/src/test/modules/injection_points/expected/fk_column_ref.out
new file mode 100644
index 00000000000..5f33cc1d1a2
--- /dev/null
+++ b/src/test/modules/injection_points/expected/fk_column_ref.out
@@ -0,0 +1,33 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_attach s1_add_fk s2_invalidate_and_wakeup
+step s1_attach: 
+	SELECT injection_points_set_local();
+	SELECT injection_points_attach('checkFkeyPermissions-after-table-acl-fail', 'wait');
+
+injection_points_set_local
+--------------------------
+                          
+(1 row)
+
+injection_points_attach
+-----------------------
+                       
+(1 row)
+
+step s1_add_fk: 
+	SET ROLE role_fk_tester;
+	ALTER TABLE fk_source ADD FOREIGN KEY (ref_id) REFERENCES fk_ref_target(id);
+	RESET ROLE;
+ <waiting ...>
+step s2_invalidate_and_wakeup: 
+	GRANT SELECT ON produce_inval TO role_fk_tester;
+	REVOKE SELECT ON produce_inval FROM role_fk_tester;
+	SELECT injection_points_wakeup('checkFkeyPermissions-after-table-acl-fail');
+
+injection_points_wakeup
+-----------------------
+                       
+(1 row)
+
+step s1_add_fk: <... completed>
diff --git a/src/test/modules/injection_points/meson.build b/src/test/modules/injection_points/meson.build
index 59dba1cb023..6c7a48edf77 100644
--- a/src/test/modules/injection_points/meson.build
+++ b/src/test/modules/injection_points/meson.build
@@ -51,6 +51,7 @@ tests += {
       'repack_toast',
       'syscache-update-pruned',
       'heap_lock_update',
+      'fk_column_ref',
     ],
     'runningcheck': false, # see syscache-update-pruned
     # Some tests wait for all snapshots, so avoid parallel execution
diff --git a/src/test/modules/injection_points/specs/fk_column_ref.spec b/src/test/modules/injection_points/specs/fk_column_ref.spec
new file mode 100644
index 00000000000..4e9307c913b
--- /dev/null
+++ b/src/test/modules/injection_points/specs/fk_column_ref.spec
@@ -0,0 +1,56 @@
+# Test that column-level REFERENCES does not trigger a false recheck failure.
+#
+# When a user has only column-level REFERENCES (not table-level),
+# checkFkeyPermissions() calls pg_class_aclcheck() which fails then falls
+# through to pg_attribute_aclcheck() which succeeds. If catalog invalidations
+# arrive before dependency recording, recheckAcl() must not spuriously fail on
+# the tracked failed check (it should not be tracked).
+
+setup
+{
+	CREATE EXTENSION injection_points;
+	CREATE TABLE fk_ref_target(id int PRIMARY KEY);
+	INSERT INTO fk_ref_target VALUES (1);
+	CREATE TABLE produce_inval(x int);
+	CREATE ROLE role_fk_tester;
+	GRANT REFERENCES(id) ON fk_ref_target TO role_fk_tester;
+	GRANT CREATE ON SCHEMA public TO role_fk_tester;
+	GRANT SELECT ON fk_ref_target TO role_fk_tester;
+	SET ROLE role_fk_tester;
+	CREATE TABLE fk_source(ref_id int);
+	INSERT INTO fk_source VALUES (1);
+	RESET ROLE;
+}
+
+teardown
+{
+	DROP TABLE IF EXISTS fk_source;
+	DROP TABLE IF EXISTS fk_ref_target;
+	DROP TABLE IF EXISTS produce_inval;
+	REVOKE CREATE ON SCHEMA public FROM role_fk_tester;
+	DROP ROLE role_fk_tester;
+	DROP EXTENSION injection_points;
+}
+
+session "s1"
+step "s1_attach" {
+	SELECT injection_points_set_local();
+	SELECT injection_points_attach('checkFkeyPermissions-after-table-acl-fail', 'wait');
+}
+step "s1_add_fk" {
+	SET ROLE role_fk_tester;
+	ALTER TABLE fk_source ADD FOREIGN KEY (ref_id) REFERENCES fk_ref_target(id);
+	RESET ROLE;
+}
+
+session "s2"
+step "s2_invalidate_and_wakeup" {
+	GRANT SELECT ON produce_inval TO role_fk_tester;
+	REVOKE SELECT ON produce_inval FROM role_fk_tester;
+	SELECT injection_points_wakeup('checkFkeyPermissions-after-table-acl-fail');
+}
+
+# s1 attaches the wait point, then starts the FK creation which blocks
+# after the failed pg_class_aclcheck. s2 generates invalidations and
+# wakes s1. The FK creation must succeed despite the invalidations.
+permutation "s1_attach" "s1_add_fk" "s2_invalidate_and_wakeup"
-- 
2.34.1

  [text/x-diff] v28-0003-Add-pg_attribute_aclcheck_ext-to-ACL-tracking-fo.patch (5.0K, ../../aj0MwjV1RKV8FvCG@bdtpg/4-v28-0003-Add-pg_attribute_aclcheck_ext-to-ACL-tracking-fo.patch)
  download | inline diff:
From d9fbfb66fc57a1cda42d6c0120bbfd5ad4516f9d Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Tue, 16 Jun 2026 07:33:39 +0000
Subject: [PATCH v28 3/5] Add pg_attribute_aclcheck_ext to ACL tracking for
 dependency recording

Add an attnum field to AclCheckEntry so that recheckAcl() can distinguish
column-level checks from table-level checks and call the appropriate recheck
function. InvalidAttrNumber means whole-object check.

This also adds tracking to pg_attribute_aclcheck_ext(), so that future DDL
paths using column-level privileges will automatically get TOCTOU protection
without needing a pre-existing lock on the table.

Currently, the only caller of pg_attribute_aclcheck_ext() that also records
dependencies on the checked object is checkFkeyPermissions(), which holds
ShareRowExclusiveLock on the referenced table. While this prevents concurrent
REVOKE ON the table itself, it does not prevent concurrent role membership
revokes. Adding tracking here provides protection against that case and future
DDL callers.

The remaining aclcheck functions (pg_parameter_aclcheck and
pg_largeobject_aclcheck_snapshot) do not need tracking: pg_parameter_aclcheck
checks GUC parameters which are not dependency targets, and
pg_largeobject_aclcheck_snapshot is only called from inv_open() and
has_largeobject_privilege(), neither of which records dependencies.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Reviewed-by: Jeff Davis <pgsql@j-davis.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/catalog/aclchk.c         | 7 +++++--
 src/backend/catalog/pg_depend.c      | 7 ++++++-
 src/include/catalog/aclcheck_track.h | 8 ++++++--
 3 files changed, 17 insertions(+), 5 deletions(-)
  64.1% src/backend/catalog/
  35.8% src/include/catalog/

diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index 02c4489f0c4..fb51ea2e869 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -3899,7 +3899,7 @@ object_aclcheck_ext(Oid classid, Oid objectid,
 	if (object_aclmask_ext(classid, objectid, roleid, mode, ACLMASK_ANY,
 						   is_missing) != 0)
 	{
-		aclcheck_track_record(classid, objectid, roleid, mode);
+		aclcheck_track_record(classid, objectid, InvalidAttrNumber, roleid, mode);
 		return ACLCHECK_OK;
 	}
 	else
@@ -3934,7 +3934,10 @@ pg_attribute_aclcheck_ext(Oid table_oid, AttrNumber attnum,
 {
 	if (pg_attribute_aclmask_ext(table_oid, attnum, roleid, mode,
 								 ACLMASK_ANY, is_missing) != 0)
+	{
+		aclcheck_track_record(RelationRelationId, table_oid, attnum, roleid, mode);
 		return ACLCHECK_OK;
+	}
 	else
 		return ACLCHECK_NO_PRIV;
 }
@@ -4104,7 +4107,7 @@ pg_class_aclcheck_ext(Oid table_oid, Oid roleid,
 	if (pg_class_aclmask_ext(table_oid, roleid, mode,
 							 ACLMASK_ANY, is_missing) != 0)
 	{
-		aclcheck_track_record(RelationRelationId, table_oid, roleid, mode);
+		aclcheck_track_record(RelationRelationId, table_oid, InvalidAttrNumber, roleid, mode);
 		return ACLCHECK_OK;
 	}
 	else
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 912c92e8fef..88a27fdc802 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -773,7 +773,12 @@ recheckAcl(Oid classId, Oid objectId)
 		{
 			AclResult	aclresult;
 
-			if (classId == RelationRelationId)
+			if (acltable->entries[i].attnum != InvalidAttrNumber)
+				aclresult = pg_attribute_aclcheck(objectId,
+												  acltable->entries[i].attnum,
+												  acltable->entries[i].roleId,
+												  acltable->entries[i].mode);
+			else if (classId == RelationRelationId)
 				aclresult = pg_class_aclcheck(objectId,
 											  acltable->entries[i].roleId,
 											  acltable->entries[i].mode);
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
index d994cf7889b..4ac65e4de5c 100644
--- a/src/include/catalog/aclcheck_track.h
+++ b/src/include/catalog/aclcheck_track.h
@@ -30,6 +30,7 @@ typedef struct AclCheckEntry
 {
 	Oid			classId;
 	Oid			objectId;
+	AttrNumber	attnum;
 	Oid			roleId;
 	AclMode		mode;
 	uint64		inval_count;
@@ -50,11 +51,13 @@ extern void FreeTrackAclTable(TrackAclTable *acltable);
 /*
  * Record an aclcheck for later revalidation.
  *
- * Called from object_aclcheck_ext() and pg_class_aclcheck_ext().
+ * Called from object_aclcheck_ext(), pg_class_aclcheck_ext(), and
+ * pg_attribute_aclcheck_ext().
  * Only records when inside an utility statement.
  */
 static inline void
-aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
+aclcheck_track_record(Oid classId, Oid objectId, AttrNumber attnum,
+					  Oid roleId, AclMode mode)
 {
 	TrackAclTable *acltable = CurrentTrackAclTable;
 	AclCheckEntry *entry;
@@ -72,6 +75,7 @@ aclcheck_track_record(Oid classId, Oid objectId, Oid roleId, AclMode mode)
 	entry = &acltable->entries[acltable->count++];
 	entry->classId = classId;
 	entry->objectId = objectId;
+	entry->attnum = attnum;
 	entry->roleId = roleId;
 	entry->mode = mode;
 	entry->inval_count = SharedInvalidMessageCounter;
-- 
2.34.1

  [text/x-diff] v28-0004-Discard-ACL-tracking-entries-from-aborted-subtra.patch (3.7K, ../../aj0MwjV1RKV8FvCG@bdtpg/5-v28-0004-Discard-ACL-tracking-entries-from-aborted-subtra.patch)
  download | inline diff:
From 1a1aa7c374a6b8a72883768aab258d8b8cb8c9e4 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Thu, 25 Jun 2026 04:16:03 +0000
Subject: [PATCH v28 4/5] Discard ACL tracking entries from aborted
 subtransactions

Store SubTransactionId in each AclCheckEntry at recording time. On
subtransaction abort, AtEOSubXact_AclTrack() discards entries whose subxid
is >= the aborting subtransaction's ID.

Author: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Discussion: https://postgr.es/m/ZiYjn0eVc7pxVY45@ip-10-97-1-34.eu-west-3.compute.internal
---
 src/backend/access/transam/xact.c    |  2 ++
 src/backend/catalog/aclchk.c         | 24 ++++++++++++++++++++++++
 src/include/catalog/aclcheck_track.h |  4 ++++
 3 files changed, 30 insertions(+)
   9.0% src/backend/access/transam/
  73.2% src/backend/catalog/
  17.7% src/include/catalog/

diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c
index de4cf96eaa2..90bee71d670 100644
--- a/src/backend/access/transam/xact.c
+++ b/src/backend/access/transam/xact.c
@@ -32,6 +32,7 @@
 #include "access/xlogrecovery.h"
 #include "access/xlogutils.h"
 #include "access/xlogwait.h"
+#include "catalog/aclcheck_track.h"
 #include "catalog/index.h"
 #include "catalog/namespace.h"
 #include "catalog/pg_enum.h"
@@ -5386,6 +5387,7 @@ AbortSubTransaction(void)
 		if (FullTransactionIdIsValid(s->fullTransactionId))
 			AtSubAbort_childXids();
 
+		AtEOSubXact_AclTrack(false, s->subTransactionId);
 		CallSubXactCallbacks(SUBXACT_EVENT_ABORT_SUB, s->subTransactionId,
 							 s->parent->subTransactionId);
 
diff --git a/src/backend/catalog/aclchk.c b/src/backend/catalog/aclchk.c
index fb51ea2e869..5bd4ecf7130 100644
--- a/src/backend/catalog/aclchk.c
+++ b/src/backend/catalog/aclchk.c
@@ -5075,3 +5075,27 @@ FreeTrackAclTable(TrackAclTable *acltable)
 	pfree(acltable->entries);
 	pfree(acltable);
 }
+
+/*
+ * AtEOSubXact_AclTrack
+ *
+ * At subtransaction abort, discard any ACL tracking entries that were added
+ * during the aborted subtransaction. This prevents stale entries from causing
+ * false permission-denied errors in recheckAcl().
+ *
+ * At subtransaction commit, do nothing, entries from committed subtransactions
+ * are valid and should be kept.
+ */
+void
+AtEOSubXact_AclTrack(bool isCommit, SubTransactionId mySubid)
+{
+	TrackAclTable *acltable = CurrentTrackAclTable;
+
+	if (acltable == NULL || isCommit)
+		return;
+
+	/* Discard entries from the aborting subtransaction and any nested ones */
+	while (acltable->count > 0 &&
+		   acltable->entries[acltable->count - 1].subxid >= mySubid)
+		acltable->count--;
+}
diff --git a/src/include/catalog/aclcheck_track.h b/src/include/catalog/aclcheck_track.h
index 4ac65e4de5c..27f6c47eb43 100644
--- a/src/include/catalog/aclcheck_track.h
+++ b/src/include/catalog/aclcheck_track.h
@@ -23,6 +23,7 @@
 #ifndef ACLCHECK_TRACK_H
 #define ACLCHECK_TRACK_H
 
+#include "access/xact.h"
 #include "storage/sinval.h"
 #include "utils/acl.h"
 
@@ -34,6 +35,7 @@ typedef struct AclCheckEntry
 	Oid			roleId;
 	AclMode		mode;
 	uint64		inval_count;
+	SubTransactionId subxid;
 } AclCheckEntry;
 
 typedef struct TrackAclTable
@@ -47,6 +49,7 @@ extern TrackAclTable *CurrentTrackAclTable;
 
 extern TrackAclTable *CreateTrackAclTable(void);
 extern void FreeTrackAclTable(TrackAclTable *acltable);
+extern void AtEOSubXact_AclTrack(bool isCommit, SubTransactionId mySubid);
 
 /*
  * Record an aclcheck for later revalidation.
@@ -79,6 +82,7 @@ aclcheck_track_record(Oid classId, Oid objectId, AttrNumber attnum,
 	entry->roleId = roleId;
 	entry->mode = mode;
 	entry->inval_count = SharedInvalidMessageCounter;
+	entry->subxid = GetCurrentSubTransactionId();
 }
 
 #endif							/* ACLCHECK_TRACK_H */
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
@ 2024-05-19 08:00                             ` Alexander Lakhin <exclusion@gmail.com>
  2024-05-21 07:22                               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  1 sibling, 1 reply; 93+ messages in thread

From: Alexander Lakhin @ 2024-05-19 08:00 UTC (permalink / raw)
  To: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>; Michael Paquier <michael@paquier.xyz>; +Cc: pgsql-hackers@lists.postgresql.org

Hello Bertrand,

15.05.2024 11:31, Bertrand Drouvot wrote:
> On Wed, May 15, 2024 at 10:14:09AM +0900, Michael Paquier wrote:
>
>> +            if (object_description)
>> +                ereport(ERROR, errmsg("%s does not exist", object_description));
>> +            else
>> +                ereport(ERROR, errmsg("a dependent object does not ex
>>
>> This generates an internal error code.  Is that intended?
> Yes, it's like when say you want to create an object in a schema that does not
> exist (see get_namespace_oid()).

AFAICS, get_namespace_oid() throws not ERRCODE_INTERNAL_ERROR,
but ERRCODE_UNDEFINED_SCHEMA:

# SELECT regtype('unknown_schema.type');
ERROR:  schema "unknown_schema" does not exist
LINE 1: SELECT regtype('unknown_schema.type');
                        ^
# \echo :LAST_ERROR_SQLSTATE
3F000

Probably, it's worth to avoid ERRCODE_INTERNAL_ERROR here in light of [1]
and [2], as these errors are not that abnormal (not Assert-like).

[1] https://www.postgresql.org/message-id/Zic_GNgos5sMxKoa%40paquier.xyz
[2] https://commitfest.postgresql.org/48/4735/

Best regards,
Alexander





^ permalink  raw  reply  [nested|flat] 93+ messages in thread

* Re: Avoid orphaned objects dependencies, take 3
  2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 10:00 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-22 10:52   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-22 12:00     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-23 04:59       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-23 16:20         ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 08:38           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-24 12:00             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 05:00               ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-25 06:00                 ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-04-25 07:20                   ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-04-30 17:00                     ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
  2024-05-09 12:20                       ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-15 01:14                         ` Re: Avoid orphaned objects dependencies, take 3 Michael Paquier <michael@paquier.xyz>
  2024-05-15 08:31                           ` Re: Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  2024-05-19 08:00                             ` Re: Avoid orphaned objects dependencies, take 3 Alexander Lakhin <exclusion@gmail.com>
@ 2024-05-21 07:22                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
  0 siblings, 0 replies; 93+ messages in thread

From: Bertrand Drouvot @ 2024-05-21 07:22 UTC (permalink / raw)
  To: Alexander Lakhin <exclusion@gmail.com>; +Cc: Michael Paquier <michael@paquier.xyz>; pgsql-hackers@lists.postgresql.org

Hi,

On Sun, May 19, 2024 at 11:00:00AM +0300, Alexander Lakhin wrote:
> Hello Bertrand,
> 
> Probably, it's worth to avoid ERRCODE_INTERNAL_ERROR here in light of [1]
> and [2], as these errors are not that abnormal (not Assert-like).
> 
> [1] https://www.postgresql.org/message-id/Zic_GNgos5sMxKoa%40paquier.xyz
> [2] https://commitfest.postgresql.org/48/4735/
> 

Thanks for mentioning the above examples, I agree that it's worth to avoid
ERRCODE_INTERNAL_ERROR here: please find attached v7 that makes use of a new
ERRCODE: ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST 

I thought about this name as it is close enough to the already existing 
"ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST" but I'm open to suggestion too.

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com

Attachments:

  [text/x-diff] v7-0001-Avoid-orphaned-objects-dependencies.patch (20.1K, ../../ZkxL0QAa6PlApSV6@ip-10-97-1-34.eu-west-3.compute.internal/2-v7-0001-Avoid-orphaned-objects-dependencies.patch)
  download | inline diff:
From 79809f88311ef1cf4e8f3250e1508fe0b7d86602 Mon Sep 17 00:00:00 2001
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
Date: Fri, 29 Mar 2024 15:43:26 +0000
Subject: [PATCH v7] Avoid orphaned objects dependencies

It's currently possible to create orphaned objects dependencies, for example:

Scenario 1:

session 1: begin; drop schema schem;
session 2: create a function in the schema schem
session 1: commit;

With the above, the function created in session 2 would be linked to a non
existing schema.

Scenario 2:

session 1: begin; create a function in the schema schem
session 2: drop schema schem;
session 1: commit;

With the above, the function created in session 1 would be linked to a non
existing schema.

To avoid those scenarios, a new lock (that conflicts with a lock taken by DROP)
has been put in place when the dependencies are being recorded. With this in
place, the drop schema in scenario 2 would be locked.

Also, after the new lock attempt, the patch checks that the object still exists:
with this in place session 2 in scenario 1 would be locked and would report an
error once session 1 committs (that would not be the case should session 1 abort
the transaction).

If the object is dropped before the new lock attempt is triggered then the patch
would also report an error (but with less details).

The patch adds a few tests for some dependency cases (that would currently produce
orphaned objects):

- schema and function (as the above scenarios)
- alter a dependency (function and schema)
- function and arg type
- function and return type
- function and function
- domain and domain
- table and type
- server and foreign data wrapper
---
 src/backend/catalog/dependency.c              |  58 ++++++++
 src/backend/catalog/objectaddress.c           |  70 ++++++++++
 src/backend/catalog/pg_depend.c               |  12 ++
 src/backend/utils/errcodes.txt                |   1 +
 src/include/catalog/dependency.h              |   1 +
 src/include/catalog/objectaddress.h           |   1 +
 .../expected/test_dependencies_locks.out      | 129 ++++++++++++++++++
 src/test/isolation/isolation_schedule         |   1 +
 .../specs/test_dependencies_locks.spec        |  89 ++++++++++++
 9 files changed, 362 insertions(+)
  24.6% src/backend/catalog/
  45.1% src/test/isolation/expected/
  28.1% src/test/isolation/specs/

diff --git a/src/backend/catalog/dependency.c b/src/backend/catalog/dependency.c
index d4b5b2ade1..89b2f18f98 100644
--- a/src/backend/catalog/dependency.c
+++ b/src/backend/catalog/dependency.c
@@ -1517,6 +1517,64 @@ AcquireDeletionLock(const ObjectAddress *object, int flags)
 	}
 }
 
+/*
+ * depLockAndCheckObject
+ *
+ * Lock the object that we are about to record a dependency on.
+ * After it's locked, verify that it hasn't been dropped while we
+ * weren't looking.  If the object has been dropped, this function
+ * does not return!
+ */
+void
+depLockAndCheckObject(const ObjectAddress *object)
+{
+	char	   *object_description;
+
+	/*
+	 * Those don't rely on LockDatabaseObject() when being dropped (see
+	 * AcquireDeletionLock()). Also it looks like they can not produce
+	 * orphaned dependent objects when being dropped.
+	 */
+	if (object->classId == RelationRelationId || object->classId == AuthMemRelationId)
+		return;
+
+	object_description = getObjectDescription(object, true);
+
+	/* assume we should lock the whole object not a sub-object */
+	LockDatabaseObject(object->classId, object->objectId, 0, AccessShareLock);
+
+	/* check if object still exists */
+	if (!ObjectByIdExist(object, false))
+	{
+		/*
+		 * It might be possible that we are creating it (for example creating
+		 * a composite type while creating a relation), so bypass the syscache
+		 * lookup and use a dirty snaphot instead to cover this scenario.
+		 */
+		if (!ObjectByIdExist(object, true))
+		{
+			/*
+			 * If the object has been dropped before we get a chance to get
+			 * its description, then emit a generic error message. That looks
+			 * like a good compromise over extra complexity.
+			 */
+			if (object_description)
+				ereport(ERROR,
+						(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+						 errmsg("%s does not exist", object_description)));
+			else
+				ereport(ERROR,
+						(errcode(ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST),
+						 errmsg("a dependent object does not exist")));
+		}
+	}
+
+	if (object_description)
+		pfree(object_description);
+
+	return;
+}
+
 /*
  * ReleaseDeletionLock - release an object deletion lock
  *
diff --git a/src/backend/catalog/objectaddress.c b/src/backend/catalog/objectaddress.c
index 7b536ac6fd..c2b873dd81 100644
--- a/src/backend/catalog/objectaddress.c
+++ b/src/backend/catalog/objectaddress.c
@@ -2590,6 +2590,76 @@ get_object_namespace(const ObjectAddress *address)
 	return oid;
 }
 
+/*
+ * ObjectByIdExist
+ *
+ * Return whether the given object exists.
+ *
+ * Works for most catalogs, if no special processing is needed.
+ */
+bool
+ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot)
+{
+	HeapTuple	tuple;
+	int			cache = -1;
+	const ObjectPropertyType *property;
+
+	if (!use_dirty_snapshot)
+	{
+		property = get_object_property_data(address->classId);
+
+		cache = property->oid_catcache_id;
+	}
+
+	if (cache >= 0)
+	{
+		/* Fetch tuple from syscache. */
+		tuple = SearchSysCache1(cache, ObjectIdGetDatum(address->objectId));
+
+		if (!HeapTupleIsValid(tuple))
+		{
+			return false;
+		}
+
+		ReleaseSysCache(tuple);
+
+		return true;
+	}
+	else
+	{
+		Relation	rel;
+		ScanKeyData skey[1];
+		SysScanDesc scan;
+		SnapshotData DirtySnapshot;
+		Snapshot	snapshot;
+
+		if (use_dirty_snapshot)
+		{
+			InitDirtySnapshot(DirtySnapshot);
+			snapshot = &DirtySnapshot;
+		}
+		else
+			snapshot = NULL;
+
+		rel = table_open(address->classId, AccessShareLock);
+
+		ScanKeyInit(&skey[0],
+					get_object_attnum_oid(address->classId),
+					BTEqualStrategyNumber, F_OIDEQ,
+					ObjectIdGetDatum(address->objectId));
+
+		scan = systable_beginscan(rel, get_object_oid_index(address->classId), true,
+								  snapshot, 1, skey);
+
+		/* we expect exactly one match */
+		tuple = systable_getnext(scan);
+		systable_endscan(scan);
+		table_close(rel, AccessShareLock);
+
+		return (HeapTupleIsValid(tuple));
+	}
+}
+
 /*
  * Return ObjectType for the given object type as given by
  * getObjectTypeDescription; if no valid ObjectType code exists, but it's a
diff --git a/src/backend/catalog/pg_depend.c b/src/backend/catalog/pg_depend.c
index 5366f7820c..f16af28429 100644
--- a/src/backend/catalog/pg_depend.c
+++ b/src/backend/catalog/pg_depend.c
@@ -108,6 +108,12 @@ recordMultipleDependencies(const ObjectAddress *depender,
 		if (isObjectPinned(referenced))
 			continue;
 
+		/*
+		 * Acquire a lock and check object still exists while recording the
+		 * dependency. XXX - Should we do so only for DEPENDENCY_NORMAL?
+		 */
+		depLockAndCheckObject(referenced);
+
 		if (slot_init_count < max_slots)
 		{
 			slot[slot_stored_count] = MakeSingleTupleTableSlot(RelationGetDescr(dependDesc),
@@ -506,6 +512,12 @@ changeDependencyFor(Oid classId, Oid objectId,
 		return 1;
 	}
 
+	/*
+	 * Acquire a lock and check object still exists while changing the
+	 * dependency.
+	 */
+	depLockAndCheckObject(&objAddr);
+
 	depRel = table_open(DependRelationId, RowExclusiveLock);
 
 	/* There should be existing dependency record(s), so search. */
diff --git a/src/backend/utils/errcodes.txt b/src/backend/utils/errcodes.txt
index 3250d539e1..60e8539fe3 100644
--- a/src/backend/utils/errcodes.txt
+++ b/src/backend/utils/errcodes.txt
@@ -271,6 +271,7 @@ Section: Class 28 - Invalid Authorization Specification
 Section: Class 2B - Dependent Privilege Descriptors Still Exist
 
 2B000    E    ERRCODE_DEPENDENT_PRIVILEGE_DESCRIPTORS_STILL_EXIST            dependent_privilege_descriptors_still_exist
+2BP02    E    ERRCODE_DEPENDENT_OBJECTS_DOES_NOT_EXIST                       dependent_objects_does_not_exist
 2BP01    E    ERRCODE_DEPENDENT_OBJECTS_STILL_EXIST                          dependent_objects_still_exist
 
 Section: Class 2D - Invalid Transaction Termination
diff --git a/src/include/catalog/dependency.h b/src/include/catalog/dependency.h
index 7eee66f810..5619b6f55e 100644
--- a/src/include/catalog/dependency.h
+++ b/src/include/catalog/dependency.h
@@ -101,6 +101,7 @@ typedef struct ObjectAddresses ObjectAddresses;
 /* in dependency.c */
 
 extern void AcquireDeletionLock(const ObjectAddress *object, int flags);
+extern void depLockAndCheckObject(const ObjectAddress *object);
 
 extern void ReleaseDeletionLock(const ObjectAddress *object);
 
diff --git a/src/include/catalog/objectaddress.h b/src/include/catalog/objectaddress.h
index 3a70d80e32..04891abcc1 100644
--- a/src/include/catalog/objectaddress.h
+++ b/src/include/catalog/objectaddress.h
@@ -53,6 +53,7 @@ extern void check_object_ownership(Oid roleid,
 								   Node *object, Relation relation);
 
 extern Oid	get_object_namespace(const ObjectAddress *address);
+extern bool ObjectByIdExist(const ObjectAddress *address, bool use_dirty_snapshot);
 
 extern bool is_objectclass_supported(Oid class_id);
 extern const char *get_object_class_descr(Oid class_id);
diff --git a/src/test/isolation/expected/test_dependencies_locks.out b/src/test/isolation/expected/test_dependencies_locks.out
new file mode 100644
index 0000000000..9b645d7aa5
--- /dev/null
+++ b/src/test/isolation/expected/test_dependencies_locks.out
@@ -0,0 +1,129 @@
+Parsed test spec with 2 sessions
+
+starting permutation: s1_begin s1_create_function_in_schema s2_drop_schema s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_schema: DROP SCHEMA testschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_schema: <... completed>
+ERROR:  cannot drop schema testschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_schema s1_create_function_in_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_schema: DROP SCHEMA testschema;
+step s1_create_function_in_schema: CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_in_schema: <... completed>
+ERROR:  schema testschema does not exist
+
+starting permutation: s1_begin s1_alter_function_schema s2_drop_alterschema s1_commit
+step s1_begin: BEGIN;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema;
+step s2_drop_alterschema: DROP SCHEMA alterschema; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_alterschema: <... completed>
+ERROR:  cannot drop schema alterschema because other objects depend on it
+
+starting permutation: s2_begin s2_drop_alterschema s1_alter_function_schema s2_commit
+step s2_begin: BEGIN;
+step s2_drop_alterschema: DROP SCHEMA alterschema;
+step s1_alter_function_schema: ALTER FUNCTION public.falter() SET SCHEMA alterschema; <waiting ...>
+step s2_commit: COMMIT;
+step s1_alter_function_schema: <... completed>
+ERROR:  schema alterschema does not exist
+
+starting permutation: s1_begin s1_create_function_with_argtype s2_drop_foo_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql;
+step s2_drop_foo_type: DROP TYPE public.foo; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_type: <... completed>
+ERROR:  cannot drop type foo because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_type s1_create_function_with_argtype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_type: DROP TYPE public.foo;
+step s1_create_function_with_argtype: CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_argtype: <... completed>
+ERROR:  type foo does not exist
+
+starting permutation: s1_begin s1_create_function_with_rettype s2_drop_foo_rettype s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1;
+step s2_drop_foo_rettype: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_foo_rettype: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_foo_rettype s1_create_function_with_rettype s2_commit
+step s2_begin: BEGIN;
+step s2_drop_foo_rettype: DROP DOMAIN id;
+step s1_create_function_with_rettype: CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_rettype: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_function_with_function s2_drop_function_f s1_commit
+step s1_begin: BEGIN;
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1;
+step s2_drop_function_f: DROP FUNCTION f(); <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_function_f: <... completed>
+ERROR:  cannot drop function f() because other objects depend on it
+
+starting permutation: s2_begin s2_drop_function_f s1_create_function_with_function s2_commit
+step s2_begin: BEGIN;
+step s2_drop_function_f: DROP FUNCTION f();
+step s1_create_function_with_function: CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_function_with_function: <... completed>
+ERROR:  function f() does not exist
+
+starting permutation: s1_begin s1_create_domain_with_domain s2_drop_domain_id s1_commit
+step s1_begin: BEGIN;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id;
+step s2_drop_domain_id: DROP DOMAIN id; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_domain_id: <... completed>
+ERROR:  cannot drop type id because other objects depend on it
+
+starting permutation: s2_begin s2_drop_domain_id s1_create_domain_with_domain s2_commit
+step s2_begin: BEGIN;
+step s2_drop_domain_id: DROP DOMAIN id;
+step s1_create_domain_with_domain: CREATE DOMAIN idid as id; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_domain_with_domain: <... completed>
+ERROR:  type id does not exist
+
+starting permutation: s1_begin s1_create_table_with_type s2_drop_footab_type s1_commit
+step s1_begin: BEGIN;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab);
+step s2_drop_footab_type: DROP TYPE public.footab; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_footab_type: <... completed>
+ERROR:  cannot drop type footab because other objects depend on it
+
+starting permutation: s2_begin s2_drop_footab_type s1_create_table_with_type s2_commit
+step s2_begin: BEGIN;
+step s2_drop_footab_type: DROP TYPE public.footab;
+step s1_create_table_with_type: CREATE TABLE tabtype(a footab); <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_table_with_type: <... completed>
+ERROR:  type footab does not exist
+
+starting permutation: s1_begin s1_create_server_with_fdw_wrapper s2_drop_fdw_wrapper s1_commit
+step s1_begin: BEGIN;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; <waiting ...>
+step s1_commit: COMMIT;
+step s2_drop_fdw_wrapper: <... completed>
+ERROR:  cannot drop foreign-data wrapper fdw_wrapper because other objects depend on it
+
+starting permutation: s2_begin s2_drop_fdw_wrapper s1_create_server_with_fdw_wrapper s2_commit
+step s2_begin: BEGIN;
+step s2_drop_fdw_wrapper: DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT;
+step s1_create_server_with_fdw_wrapper: CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; <waiting ...>
+step s2_commit: COMMIT;
+step s1_create_server_with_fdw_wrapper: <... completed>
+ERROR:  foreign-data wrapper fdw_wrapper does not exist
diff --git a/src/test/isolation/isolation_schedule b/src/test/isolation/isolation_schedule
index 0342eb39e4..1b67f0bffe 100644
--- a/src/test/isolation/isolation_schedule
+++ b/src/test/isolation/isolation_schedule
@@ -114,3 +114,4 @@ test: serializable-parallel-2
 test: serializable-parallel-3
 test: matview-write-skew
 test: lock-nowait
+test: test_dependencies_locks
diff --git a/src/test/isolation/specs/test_dependencies_locks.spec b/src/test/isolation/specs/test_dependencies_locks.spec
new file mode 100644
index 0000000000..5d04dfe9dc
--- /dev/null
+++ b/src/test/isolation/specs/test_dependencies_locks.spec
@@ -0,0 +1,89 @@
+setup
+{
+  CREATE SCHEMA testschema;
+  CREATE SCHEMA alterschema;
+  CREATE TYPE public.foo as enum ('one', 'two');
+  CREATE TYPE public.footab as enum ('three', 'four');
+  CREATE DOMAIN id AS int;
+  CREATE FUNCTION f() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FUNCTION public.falter() RETURNS int LANGUAGE SQL RETURN 1;
+  CREATE FOREIGN DATA WRAPPER fdw_wrapper;
+}
+
+teardown
+{
+  DROP FUNCTION IF EXISTS testschema.foo();
+  DROP FUNCTION IF EXISTS fooargtype(num foo);
+  DROP FUNCTION IF EXISTS footrettype();
+  DROP FUNCTION IF EXISTS foofunc();
+  DROP FUNCTION IF EXISTS public.falter();
+  DROP FUNCTION IF EXISTS alterschema.falter();
+  DROP DOMAIN IF EXISTS idid;
+  DROP SERVER IF EXISTS srv_fdw_wrapper;
+  DROP TABLE IF EXISTS tabtype;
+  DROP SCHEMA IF EXISTS testschema;
+  DROP SCHEMA IF EXISTS alterschema;
+  DROP TYPE IF EXISTS public.foo;
+  DROP TYPE IF EXISTS public.footab;
+  DROP DOMAIN IF EXISTS id;
+  DROP FUNCTION IF EXISTS f();
+  DROP FOREIGN DATA WRAPPER IF EXISTS fdw_wrapper;
+}
+
+session "s1"
+
+step "s1_begin" { BEGIN; }
+step "s1_create_function_in_schema" { CREATE FUNCTION testschema.foo() RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_argtype" { CREATE FUNCTION fooargtype(num foo) RETURNS int AS 'select 1' LANGUAGE sql; }
+step "s1_create_function_with_rettype" { CREATE FUNCTION footrettype() RETURNS id LANGUAGE sql RETURN 1; }
+step "s1_create_function_with_function" { CREATE FUNCTION foofunc() RETURNS int LANGUAGE SQL RETURN f() + 1; }
+step "s1_alter_function_schema" { ALTER FUNCTION public.falter() SET SCHEMA alterschema; }
+step "s1_create_domain_with_domain" { CREATE DOMAIN idid as id; }
+step "s1_create_table_with_type" { CREATE TABLE tabtype(a footab); }
+step "s1_create_server_with_fdw_wrapper" { CREATE SERVER srv_fdw_wrapper FOREIGN DATA WRAPPER fdw_wrapper; }
+step "s1_commit" { COMMIT; }
+
+session "s2"
+
+step "s2_begin" { BEGIN; }
+step "s2_drop_schema" { DROP SCHEMA testschema; }
+step "s2_drop_alterschema" { DROP SCHEMA alterschema; }
+step "s2_drop_foo_type" { DROP TYPE public.foo; }
+step "s2_drop_foo_rettype" { DROP DOMAIN id; }
+step "s2_drop_footab_type" { DROP TYPE public.footab; }
+step "s2_drop_function_f" { DROP FUNCTION f(); }
+step "s2_drop_domain_id" { DROP DOMAIN id; }
+step "s2_drop_fdw_wrapper" { DROP FOREIGN DATA WRAPPER fdw_wrapper RESTRICT; }
+step "s2_commit" { COMMIT; }
+
+# function - schema
+permutation "s1_begin" "s1_create_function_in_schema" "s2_drop_schema" "s1_commit"
+permutation "s2_begin" "s2_drop_schema" "s1_create_function_in_schema" "s2_commit"
+
+# alter function - schema
+permutation "s1_begin" "s1_alter_function_schema" "s2_drop_alterschema" "s1_commit"
+permutation "s2_begin" "s2_drop_alterschema" "s1_alter_function_schema" "s2_commit"
+
+# function - argtype
+permutation "s1_begin" "s1_create_function_with_argtype" "s2_drop_foo_type" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_type" "s1_create_function_with_argtype" "s2_commit"
+
+# function - rettype
+permutation "s1_begin" "s1_create_function_with_rettype" "s2_drop_foo_rettype" "s1_commit"
+permutation "s2_begin" "s2_drop_foo_rettype" "s1_create_function_with_rettype" "s2_commit"
+
+# function - function
+permutation "s1_begin" "s1_create_function_with_function" "s2_drop_function_f" "s1_commit"
+permutation "s2_begin" "s2_drop_function_f" "s1_create_function_with_function" "s2_commit"
+
+# domain - domain
+permutation "s1_begin" "s1_create_domain_with_domain" "s2_drop_domain_id" "s1_commit"
+permutation "s2_begin" "s2_drop_domain_id" "s1_create_domain_with_domain" "s2_commit"
+
+# table - type
+permutation "s1_begin" "s1_create_table_with_type" "s2_drop_footab_type" "s1_commit"
+permutation "s2_begin" "s2_drop_footab_type" "s1_create_table_with_type" "s2_commit"
+
+# server - foreign data wrapper
+permutation "s1_begin" "s1_create_server_with_fdw_wrapper" "s2_drop_fdw_wrapper" "s1_commit"
+permutation "s2_begin" "s2_drop_fdw_wrapper" "s1_create_server_with_fdw_wrapper" "s2_commit"
-- 
2.34.1

^ permalink  raw  reply  [nested|flat] 93+ messages in thread


end of thread, other threads:[~2026-06-25 11:10 UTC | newest]

Thread overview: 93+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-04-22 08:45 Avoid orphaned objects dependencies, take 3 Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-04-22 10:00 ` Alexander Lakhin <exclusion@gmail.com>
2024-04-22 10:52   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-04-22 12:00     ` Alexander Lakhin <exclusion@gmail.com>
2024-04-23 04:59       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-04-23 16:20         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-04-24 08:38           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-04-24 12:00             ` Alexander Lakhin <exclusion@gmail.com>
2024-04-25 05:00               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-04-25 06:00                 ` Alexander Lakhin <exclusion@gmail.com>
2024-04-25 07:20                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-04-30 17:00                     ` Alexander Lakhin <exclusion@gmail.com>
2024-05-09 12:20                       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-05-14 12:00                         ` Alexander Lakhin <exclusion@gmail.com>
2024-05-15 08:33                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-05-15 01:14                         ` Michael Paquier <michael@paquier.xyz>
2024-05-15 08:31                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-05-15 10:31                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-05-21 12:53                               ` Robert Haas <robertmhaas@gmail.com>
2024-05-22 10:21                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-05-22 14:48                                   ` Robert Haas <robertmhaas@gmail.com>
2024-05-23 04:19                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-05-23 18:10                                       ` Robert Haas <robertmhaas@gmail.com>
2024-05-23 21:12                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-06-06 05:56                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-06-06 20:00                                           ` Robert Haas <robertmhaas@gmail.com>
2024-06-07 08:41                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-06-13 14:49                                               ` Robert Haas <robertmhaas@gmail.com>
2024-06-13 16:52                                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-06-13 18:27                                                   ` Robert Haas <robertmhaas@gmail.com>
2024-06-14 07:54                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-06-17 16:24                                                       ` Robert Haas <robertmhaas@gmail.com>
2024-06-17 17:57                                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-06-19 11:49                                                           ` Ashutosh Sharma <ashu.coek88@gmail.com>
2024-06-19 12:20                                                             ` Robert Haas <robertmhaas@gmail.com>
2024-06-19 13:35                                                               ` Ashutosh Sharma <ashu.coek88@gmail.com>
2024-06-19 14:11                                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-06-21 13:22                                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-06-26 10:24                                                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-07-01 09:39                                                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-07-02 05:56                                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-07-10 07:31                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-08-19 15:35                                                                       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-10-28 09:30                                                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-01-02 08:15                                                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-02-04 13:24                                                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-05-23 04:20                                                                               ` jian he <jian.universality@gmail.com>
2024-06-17 10:50                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-05-19 17:02                                     ` Jeff Davis <pgsql@j-davis.com>
2025-05-19 18:07                                       ` Robert Haas <robertmhaas@gmail.com>
2025-05-20 21:12                                         ` Jeff Davis <pgsql@j-davis.com>
2025-05-21 06:37                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-05-21 16:55                                           ` Robert Haas <robertmhaas@gmail.com>
2025-05-21 17:17                                             ` Jeff Davis <pgsql@j-davis.com>
2025-05-21 17:47                                               ` Robert Haas <robertmhaas@gmail.com>
2025-05-22 12:15                                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-05-22 13:40                                                 ` Robert Haas <robertmhaas@gmail.com>
2025-05-22 19:38                                                   ` Jeff Davis <pgsql@j-davis.com>
2025-06-02 14:06                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-06-02 14:02                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-06-03 17:27                                                     ` Robert Haas <robertmhaas@gmail.com>
2025-06-06 05:37                                                       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2025-11-09 08:33                                                         ` Roman Eskin <r.eskin@arenadata.io>
2026-04-15 18:36                                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-04-28 11:17                                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-05-13 20:20                                                               ` Robert Haas <robertmhaas@gmail.com>
2026-05-18 12:14                                                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-05-26 18:00                                                                   ` Heikki Linnakangas <hlinnaka@iki.fi>
2026-05-26 20:18                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-05-27 15:53                                                                       ` Heikki Linnakangas <hlinnaka@iki.fi>
2026-06-01 09:21                                                                         ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-03 18:08                                                                           ` Jeff Davis <pgsql@j-davis.com>
2026-06-04 17:17                                                                             ` Jeff Davis <pgsql@j-davis.com>
2026-06-05 13:12                                                                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-04 17:03                                                                           ` Jeff Davis <pgsql@j-davis.com>
2026-06-05 13:09                                                                             ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-08 21:55                                                                               ` Jeff Davis <pgsql@j-davis.com>
2026-06-09 06:47                                                                                 ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-09 18:04                                                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-09 21:44                                                                                   ` Jeff Davis <pgsql@j-davis.com>
2026-06-10 12:31                                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-10 15:16                                                                                       ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-16 01:19                                                                                         ` Jeff Davis <pgsql@j-davis.com>
2026-06-16 10:09                                                                                           ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-16 19:14                                                                                             ` Jeff Davis <pgsql@j-davis.com>
2026-06-17 05:44                                                                                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-18 23:21                                                                                                 ` Jeff Davis <pgsql@j-davis.com>
2026-06-19 02:13                                                                                                   ` Jeff Davis <pgsql@j-davis.com>
2026-06-19 13:36                                                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-19 13:28                                                                                                   ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2026-06-25 11:10                                                                                                     ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
2024-05-19 08:00                             ` Alexander Lakhin <exclusion@gmail.com>
2024-05-21 07:22                               ` Bertrand Drouvot <bertranddrouvot.pg@gmail.com>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox