Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wf8yQ-005I9d-2A for pgsql-hackers@arkaria.postgresql.org; Thu, 02 Jul 2026 04:24:26 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wf8xP-00HBHe-0F for pgsql-hackers@arkaria.postgresql.org; Thu, 02 Jul 2026 04:23:23 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wf8xO-00HBHW-2Z for pgsql-hackers@lists.postgresql.org; Thu, 02 Jul 2026 04:23:22 +0000 Received: from mail-wm1-x330.google.com ([2a00:1450:4864:20::330]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1wf8xM-00000001JSV-0G0y for pgsql-hackers@lists.postgresql.org; Thu, 02 Jul 2026 04:23:22 +0000 Received: by mail-wm1-x330.google.com with SMTP id 5b1f17b1804b1-490cf322ed0so8687355e9.1 for ; Wed, 01 Jul 2026 21:23:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782966198; x=1783570998; darn=lists.postgresql.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=wkwnwD/lMcfz313VoOMqvbaE6BK7SQpS7FNYI/wJ/v0=; b=Jf6zkoRneDfes7vPBhmzh+kH988xqg7/ujyFzi+iyAlfrF3ydjI6tL2cYhj6100XBG AyFydaComnpEpIMY5j9tkFUe8pWi4/Z1KmAj7PRgodkhWZTGdXIHRgvrCvcFeoABCwOS MAOmS8r5tBYDuDVAcqjxZOVFfJU+jGH5vBuqjl5+8puI0q5uo9kryLS62nndVZf9nCr6 0YGRtcF7MqERdcNJFqW3ZjqoYhDxvFBtFLdr0EKKMw9z+U/nXGAlQMcNTUOIWyOCRX55 iQ6+7y5PGqTdmyGel27DF3FzIhhrZDtHd162KmifsDY1rADXk8uc32Xq8Np5VrZzMWAH 3TsQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782966198; x=1783570998; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=wkwnwD/lMcfz313VoOMqvbaE6BK7SQpS7FNYI/wJ/v0=; b=fYAIK1JelgfmGlwRvdwSaDBnEjEUXz0QSITIwMQB7xRyShqdYZB5ET1XVSP7Mt9v2k 5C3hJazFp6oOsVCn4IsiVsc8g7feNQ1fwoEGRY5oLYH3lyVFOzro3a0eNstsWr3mBdQS rSNUb5QDiAN4IZVFXPjq3XXZl5RMPlVJxGyCmXF3NMCTgX+Eu0/M3cDoapMWfjEIda3r KNHTElLaC6phYwRih8t9H0sLnMtYG00CLi7X2hmwopsUqfVVnM6lSxa4ST5jmcUp3gqh exQVgMjC0eB6+4p6BVTLHbwvjMJOYOKspo7tnDi/lGzx09uPQNvvg8t8+qJ1pGfqZI88 XwhA== X-Forwarded-Encrypted: i=1; AFNElJ9s4pHLQDhIKX7kUK9Z2CmuSZsuiQPCuomIag1c8zKDYfZbcECv8ukJv+jWKXy9cySGrGyYDaQ6rYdlBUOw@lists.postgresql.org X-Gm-Message-State: AOJu0YyEMOXmhe2DXFEUd9ZH5fI+rGLf7qya7ahRv8WdEdxIo1O1LK/4 pIa16IjBvXv3c+wKHNWohZnM/q+XhuiZs7GZqPm6B2rJmmGfzaW+VlPn X-Gm-Gg: AfdE7cmsLgCnj1klMQW2fyNn2fiAM1nGEs/pj5Mo18c7uJGpWSXxv6ghYaq3CmaU6ob crjqm4hfT2DnNCM3NEJ9S+NcmPHULStGPBxuAz567D9vjF40mO+QH/4KDn7CovqLfa8bEXLEYsz Fqlp2jge9USWVqNVgLfiDtM3DjMnEikgbM+m+pzM+HTkKvBauIMQVwScyxG3OZG8o9GjJ/XwQM6 yY2umuQcWQFOOQIBeawrnnnQxsqXhUCNcbXX3iIHkP4i93+s81fCBl8j28vE6EZKxGuL5N6xInd DCxvAK4mGd41Bya/dWkabcMgRm75iu3w2uXD/S0Vp2FL9V8dLpmtGpBwL7pkOvivBMeEQt9gXOj Maph5mAHQ2MiyQiQ1kAMV8W9nSpZIDMt68RqoetLwZ09rIdxP9L0YKjrLLStTNuYasStNivzMOK nyzGwnK+Yw3KrLnul1ooKE8DKkgp4kWqe5AhW+1ixc5uIOXxQnBpP/+dKcSUtkN03q40PEAeDv X-Received: by 2002:a05:600c:6c95:b0:493:bc4a:fb56 with SMTP id 5b1f17b1804b1-493c2bbcb21mr46932195e9.39.1782966198382; Wed, 01 Jul 2026 21:23:18 -0700 (PDT) Received: from bdtpg (ec2-15-237-197-144.eu-west-3.compute.amazonaws.com. [15.237.197.144]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-493bef183e7sm121313255e9.2.2026.07.01.21.23.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 01 Jul 2026 21:23:18 -0700 (PDT) Date: Thu, 2 Jul 2026 04:23:16 +0000 From: Bertrand Drouvot To: Michael Paquier Cc: Ewan Young , pgsql-hackers@lists.postgresql.org Subject: Re: Prevent crash when calling pgstat functions with unregistered stats kind Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Hi, On Thu, Jul 02, 2026 at 01:10:18PM +0900, Michael Paquier wrote: > On Thu, Jul 02, 2026 at 04:06:01AM +0000, Bertrand Drouvot wrote: > > I agree that the responsibility should primarily be in the extension. However, > > the issue is that the NULL dereference happens inside core code (pgstat_prep_pending_entry, > > etc.), and the resulting segfault(s) cause the postmaster to terminate all > > backends (not just the offending session). > > > > Given that one misconfigured extension can crash all connections on the server, > > a defensive check in core seems reasonable (kind of similar to 341e9a05e7b). > > Nope, this was a different thing, doable in a couple of steps: > - Load the library. > - Write custom stats. > - Stop the server, flush the stats. > - Edit the configuration, not loading the library. > - Restart the server, loading failed. > > The problem of this thread ought to be blocked at its source, in the > extension itself: let's not give free hands to an extension to do what > it should not be allowed to do. There is a similar defense in > test_custom_rmgrs, as one example. We should just map to that. Ok but what about extensions that don't call pgstat_register_kind() at all? Your point is that they would see the issue during the development of the extension? (If so, I think I could agree). Regards, -- Bertrand Drouvot PostgreSQL Contributors Team RDS Open Source Databases Amazon Web Services: https://aws.amazon.com