agora inbox for pgsql-hackers@postgresql.org
help / color / mirror / Atom feedFrom: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
To: Michael Paquier <michael@paquier.xyz>
Cc: Ewan Young <kdbase.hack@gmail.com>
Cc: pgsql-hackers@lists.postgresql.org
Subject: Re: Prevent crash when calling pgstat functions with unregistered stats kind
Date: Thu, 2 Jul 2026 04:23:16 +0000
Message-ID: <akXntNv2344hoc6L@bdtpg> (raw)
In-Reply-To: <akXkqov6wLbKwpAd@paquier.xyz>
References: <akS/ldidWeqG1FWk@bdtpg>
<CAON2xHOA23Oq8EERoV9ERBZof1O_vN-tYf0q58TwdkrTNZ-SPg@mail.gmail.com>
<akXalpb3zjPX3ZEl@bdtpg>
<akXebziFr_eQgQi8@paquier.xyz>
<akXjqbXRTLNcwHyE@bdtpg>
<akXkqov6wLbKwpAd@paquier.xyz>
Hi,
On Thu, Jul 02, 2026 at 01:10:18PM +0900, Michael Paquier wrote:
> On Thu, Jul 02, 2026 at 04:06:01AM +0000, Bertrand Drouvot wrote:
> > I agree that the responsibility should primarily be in the extension. However,
> > the issue is that the NULL dereference happens inside core code (pgstat_prep_pending_entry,
> > etc.), and the resulting segfault(s) cause the postmaster to terminate all
> > backends (not just the offending session).
> >
> > Given that one misconfigured extension can crash all connections on the server,
> > a defensive check in core seems reasonable (kind of similar to 341e9a05e7b).
>
> Nope, this was a different thing, doable in a couple of steps:
> - Load the library.
> - Write custom stats.
> - Stop the server, flush the stats.
> - Edit the configuration, not loading the library.
> - Restart the server, loading failed.
>
> The problem of this thread ought to be blocked at its source, in the
> extension itself: let's not give free hands to an extension to do what
> it should not be allowed to do. There is a similar defense in
> test_custom_rmgrs, as one example. We should just map to that.
Ok but what about extensions that don't call pgstat_register_kind() at all? Your
point is that they would see the issue during the development of the extension? (If
so, I think I could agree).
Regards,
--
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com
view thread (13+ messages) latest in thread
Message-ID: <akXntNv2344hoc6L@bdtpg>
Permalink: ../akXntNv2344hoc6L@bdtpg/
Also on: postgresql.org/message-id/akXntNv2344hoc6L@bdtpg
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-hackers@postgresql.org
Cc: bertranddrouvot.pg@gmail.com, michael@paquier.xyz, kdbase.hack@gmail.com, pgsql-hackers@lists.postgresql.org
Subject: Re: Prevent crash when calling pgstat functions with unregistered stats kind
In-Reply-To: <akXntNv2344hoc6L@bdtpg>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox