Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wf8gk-005How-39 for pgsql-hackers@arkaria.postgresql.org; Thu, 02 Jul 2026 04:06:10 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wf8gj-00GyVp-0c for pgsql-hackers@arkaria.postgresql.org; Thu, 02 Jul 2026 04:06:09 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wf8gi-00GyVh-2w for pgsql-hackers@lists.postgresql.org; Thu, 02 Jul 2026 04:06:08 +0000 Received: from mail-wm1-x336.google.com ([2a00:1450:4864:20::336]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1wf8gg-00000001JG9-24Dw for pgsql-hackers@lists.postgresql.org; Thu, 02 Jul 2026 04:06:08 +0000 Received: by mail-wm1-x336.google.com with SMTP id 5b1f17b1804b1-493c1950518so467715e9.1 for ; Wed, 01 Jul 2026 21:06:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782965163; x=1783569963; darn=lists.postgresql.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=pPlATgcRGMX203iahIshXYwa8nsw6u/icrL+jlYh5Yg=; b=jw775dFk2jkKmsIUdKediC2CJM9lI5PlcF+4AqZkcD5ECK2mX+5vqP5iv9mwIP3SdE YVOmQvdcHEgK6D3i3bBkwkyqUeLFv9LYHME5yb9EcJxCe5ZxAKB46th4S1rOkuSj6ccS OZcFNwjGXcfpiOSaCdVFUvVVh6K++i3SnX3grcuhVsQRlJVxOfXoX/AeWiD8EjOXI0Di 5QJ/CostiulyGQ9nVP9L2QG2AzSrxPkh5ufo2jSUCqldoGxcGb7N7wDMjlkX99+RyvsR OOf92VrI45t9dUA9gLdhj0ev4qLKMgGoj7iGzDoaVU304ese44R1xFds6IU/MbLmX6Xi dmpA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782965163; x=1783569963; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=pPlATgcRGMX203iahIshXYwa8nsw6u/icrL+jlYh5Yg=; b=tCjQsbTYBi7N2Ov5+1LOMPaG2Mix8WdA6f+C40uzq7RVL/EwZB4LIUkOlH8AAMvcBn kOBPwwDMoSCsZmfX4YAdabXg1q/hkaeYrDHJ0O2nuII1DwDSoiGUfad3C/pmT4150NHo 42DfBccusJv4CpAyiK0NaFE8JtKAyVU5Gm83YkyL6svbHySnQLHxBG05YaouRs2HOkOl upUOpvrNsHM4nqINZL1eYcH13hg4OibZOsMXqHdxRMB1h4anRANXCgtfDyWsligP92fA y7w3x4YoxptKyrQVhhW+w4L5J/FChXAcsjkcaTsrGuRHbbzmkadfwQSKJ03KzurrZqLA vQNQ== X-Forwarded-Encrypted: i=1; AFNElJ9euzouH6t5kEOarXabPwdUJMna3qh4YQlHegKgdtHVsi+p3AFADKenhOLQVR44egaU4Xc5L6e6Op5brPtr@lists.postgresql.org X-Gm-Message-State: AOJu0YyHaMciwF+zISdJ6vMpXXpZkEo8yyQWDH3iPohXQNeK8WnlRq34 64DYNNxniv8px+YERA4mNpJOiNgWGXOWorMOzK/56eZgCweAcrWxldk+ X-Gm-Gg: AfdE7cm30hKqRQpPC+VEQJxq8br5H1PCho2vfnRwm8YJol0z2HkYaJaqNUiCklTLuku dOLHeSsC9gJx2B9v0KGGIFlFUQTziSIVx7SVM2AY8rwBfIFNaLpYlYnC35Ci5RdG/dGTiJGbly0 lRG6vyYUWPZ2zYAaT2hz7V8JapD2hBNpIkcGmVuxbWE/znEe/pwAjL+J1XCSZzwKSL/v7hKhneG AO3UmRiRxF8tNxW+RGuMOQ7L+R7UOn6K8QyEpdkw8IIayIXbBQOJZMYgmW3D+D6GpgGtdACdq+T zcdqOzy6OSrIpogPQc0YiY/SGqQNvebYZwhyDVY0dpR0ub3WPpcparxjHg3dlmxb9YUD39f7fmK QnsynbdwSnZZWJi6zsOxOq+2La5LXTM1iAUApg9kqm4lpopTeUwMquwVGyB8doxR0OtUS/ihZIM Pqq3GdKhvljg7CJS3cb4egRERNET2mHWWWI11UtfJlpqGOV9Q2XHhF8axQ7vB5raaYNrSA/lKv X-Received: by 2002:a05:600c:4685:b0:490:af63:2cb1 with SMTP id 5b1f17b1804b1-493c231f913mr57333055e9.7.1782965163207; Wed, 01 Jul 2026 21:06:03 -0700 (PDT) Received: from bdtpg (ec2-15-237-197-144.eu-west-3.compute.amazonaws.com. [15.237.197.144]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-493c63648d7sm13910765e9.7.2026.07.01.21.06.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 01 Jul 2026 21:06:02 -0700 (PDT) Date: Thu, 2 Jul 2026 04:06:01 +0000 From: Bertrand Drouvot To: Michael Paquier Cc: Ewan Young , pgsql-hackers@lists.postgresql.org Subject: Re: Prevent crash when calling pgstat functions with unregistered stats kind Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Hi, On Thu, Jul 02, 2026 at 12:43:43PM +0900, Michael Paquier wrote: > On Thu, Jul 02, 2026 at 03:27:18AM +0000, Bertrand Drouvot wrote: > > On Wed, Jul 01, 2026 at 04:20:39PM +0800, Ewan Young wrote: > >> One small thing: in pgstat_snapshot_fixed(), the existing > >> Assert(pgstat_is_kind_valid(kind)); becomes redundant after the new NULL > >> check. A non-NULL kind_info already implies the kind is valid (that's the > >> only way pgstat_get_kind_info() returns non-NULL), so the assert can never > >> fire. Might as well drop it and keep just the fixed_amount one. > > > > Yeah good catch, done in the attached. > > I am not convinced that it is worth bothering in the core code about > this class of failures; they are just not interesting, and impossible > to miss. > > It seems to me that this error is in the _PG_init() of the modules in > modules/test_custom_stats/: we should not bypass the > pgstat_register_kind() if not loading the library from > shared_preload_libraries, but let the call happen and fail. I agree that the responsibility should primarily be in the extension. However, the issue is that the NULL dereference happens inside core code (pgstat_prep_pending_entry, etc.), and the resulting segfault(s) cause the postmaster to terminate all backends (not just the offending session). Given that one misconfigured extension can crash all connections on the server, a defensive check in core seems reasonable (kind of similar to 341e9a05e7b). Regards, -- Bertrand Drouvot PostgreSQL Contributors Team RDS Open Source Databases Amazon Web Services: https://aws.amazon.com