Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wynVx-003d5f-2X for pgsql-hackers@arkaria.postgresql.org; Tue, 25 Aug 2026 09:32:17 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wynVw-00744T-1q for pgsql-hackers@arkaria.postgresql.org; Tue, 25 Aug 2026 09:32:16 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wynVw-00744L-0r for pgsql-hackers@lists.postgresql.org; Tue, 25 Aug 2026 09:32:16 +0000 Received: from mail-wr1-x42d.google.com ([2a00:1450:4864:20::42d]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1wynVt-000000019xm-2ebs for pgsql-hackers@lists.postgresql.org; Tue, 25 Aug 2026 09:32:15 +0000 Received: by mail-wr1-x42d.google.com with SMTP id ffacd0b85a97d-47c2b362ee2so3323380f8f.1 for ; Tue, 25 Aug 2026 02:32:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787650331; x=1788255131; darn=lists.postgresql.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:from:to:cc:subject:date:message-id:reply-to:content-type; bh=eBUkB8PhX9LOcnq56mju0K+SAO0pWkzh5c40FHWcbjU=; b=DGbqTGZGIZHfae+WoLkwVd6p3V6sijU1NpBGl9YHbmyv8AzOJWsI1+8Z9DiOioHPay Z8+XIJ9AuezCYNJcXSS81z7o0RGYTXawQdWlcC5Koog2tR3KCEQ77KfVif49XWYRcRdl vTflxVjBwKiBCnNj9QS/QmTGrleZUqvlMuMbF59N6W92WazDZ3W+PZop2rzJMJCr8Bae 5w6zmniT0FRymb/zjzudMNREi4H6ItEVlLq9yC75F6M3RIJTocP+3mbt6WIfrZPeXvAw HuzBOR0YSlfnbjb3Tg8AfWQv62NSXokdyqwmpiIH2544z5ZzBmk3l5itGB1lf7uziss1 /6hw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787650331; x=1788255131; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=eBUkB8PhX9LOcnq56mju0K+SAO0pWkzh5c40FHWcbjU=; b=elgVycU7rmpqEapV4zQ1OaHV9odM9Ae6cR5glE+Kx1cPwR9dpWAmYV6q2pNSXxtPMq VbYc+gxDCZFaeTeHk40cjX94tcG/ZNG/BNDBLFmVFPuKwSUjpIOl8/PZB9DMCSLib3G4 QhbVYNOhEoOiGq+miHFt5tF9TxRALcFbwr1NTeJBBofY4iTgO/kvfSCgyAiJNE3kRZnJ a5xqgG0MQRmYRRXawAaJuWJOLMQaoFPj1m/8xcWM4vEc1hrwCuGTd09631OF1SY6lr6R R83kHVivn+oL3Q2nqlpmRuEDokFCqdER3PYlhDedD8vgDoADK2LEor0C9wVaM1feNWoL fxSQ== X-Gm-Message-State: AFuF++kXy7/8TDA0u3bK61cI9+Ul2d5zzPuHEIxOGpK1W2a9FmTOPfMd tGVlUuPQO+Ddzmdx1kw//jKdzJhU8kSMrX0sXb0HhR5irwj60v4FyiZfsQaLxg== X-Gm-Gg: AR+sD13u+gLYJmyEChNWWxkSBl8Is+mt3362ViNYUeVeo0pDAdWNv0YVVcb19zpCDVV 3RVCPbn94yuLpz4YLuKpy2MapuMmGq0dKO9g6thAh/Z2YjaRGcMng+Ts92SeM8GbS1x5lNRYMgG H23qzwktvgx3cRWjoFl5pTvm79Ylvzv1INrq/PNaV3uz3gerGFDG3vFHltsiac5RXsFQbZ+VRqX /nzkdjaNWynLOpXfnW6x2lcnL+80Y6kBBMKRQduylJPG+0O8V/ygCVP+EUkdP2wrXQGtelLEKDQ 5Hc9/03Re5s0kXpK6ZpLd3dJN/5naassMXg5z5bp8qKAFH6LbzVtjrbW6WKsNa0pHDDZqbUWIEj KRO2knF0yH2aBBfmpno9xjhAVvbgFxsCTvJh/mZesMU3omiiD2qGMdY+NeiqpeE5PzoQmnUmsJa rYH8tDRRNt3H4/ZHHcy6toijQe3xa7XM05pjGqtGOTYcEizhusVY8B7qJ7QcEQlPrWvPvk0MN8j bJpZeap9HiJgULVwK6LvTQQSftc3AM8inBUypb/ondZEHYf X-Received: by 2002:a5d:588b:0:b0:482:a053:ebf with SMTP id ffacd0b85a97d-482c81c62cemr26984970f8f.19.1787650330337; Tue, 25 Aug 2026 02:32:10 -0700 (PDT) Received: from bdtpg (ec2-15-237-197-144.eu-west-3.compute.amazonaws.com. [15.237.197.144]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9c14dadsm11087998f8f.37.2026.08.25.02.32.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 02:32:09 -0700 (PDT) Date: Tue, 25 Aug 2026 09:32:08 +0000 From: Bertrand Drouvot To: Peter Geoghegan Cc: PostgreSQL Hackers , Andres Freund , scott@scottray.io Subject: Re: Snapshot export on a standby corrupts hint bits on subxact overflow Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Hi, On Mon, Aug 24, 2026 at 07:07:07PM -0400, Peter Geoghegan wrote: > On Wed, Jul 29, 2026 at 5:36 AM Bertrand Drouvot > wrote: > > > 1/ In ExportSnapshot(), do not include recovery subxip entries and committed > > > child XIDs at or above xmax when counting and serializing them, so unnecessary > > > entries do not consume the limited recovery subxip capacity. > > That is a valid issue, but I wonder if it's worth including in a > back-patchable fix. Is the special case worth the added risk? Yeah, probably not. What about adding an XXX here: + /* + * Ignore the subxid array if it has overflowed, unless the snapshot was + * taken during recovery - in that case, top-level XIDs are in subxip as + * well, and we mustn't lose them. CopySnapshot() and SerializeSnapshot() + * make the same exception. + */ Like: " * XXX: After promotion, an imported recovery snapshot can have subxip * entries and committed children at or above xmax. These entries cannot * affect visibility, but can make sxcnt exceed * GetMaxSnapshotSubxidCount(), causing ImportSnapshot() to reject a * snapshot we exported. Filtering entries outside [xmin, xmax) would avoid that. " so that we don't forget about it? > Attached v3 simplifies 0001, partly by leaving that part out entirely. Thanks for the new version! Yeah, it looks simpler, let's keep it that way. > It also simplifies the logic by always writing "sof:%u" and "sxcnt:%d" > to the temp file -- the idea is to make ImportSnapshot import any > subxacts it finds in the file (while still sanitizing the inputs). Good idea! That makes sense to me. The format change is safe to backpatch too, since exported snapshot files are removed at startup. > Maybe we could improve the error message, but I want the committed > solution to be as simple as possible. That makes sense. I'm not sure we should modify the error message in this commit, let's keep the patch focus on fixing the bug? > > > 2/ In pg_current_snapshot(), do not include source XIDs outside [xmin, xmax), > > > so that it enforces the rule regardless of how the source snapshot was produced. > > I'm not treating this one as a priority, so I haven't worked on it. > > I'm focused on committing 0001 in the next few days, since it's a bug > that has caused users real harm. Sounds good! I looked at v3 and LGTM. Regards, -- Bertrand Drouvot PostgreSQL Contributors Team RDS Open Source Databases Amazon Web Services: https://aws.amazon.com