agora inbox for pgsql-hackers@postgresql.org  
help / color / mirror / Atom feed
[PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
645+ messages / 2 participants
[nested] [flat]

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory after
advancing minRecoveryPoint to the checkpoint, and advancing it further
if replay has progressed past the checkpoint.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 29 ++++++++++++++++++++++++++---
 1 file changed, 26 insertions(+), 3 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ec639054620 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7868,11 +7868,34 @@ CreateRestartPoint(int flags)
 			{
 				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
 				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+			}
+
+			/*
+			 * Also advance minRecoveryPoint past any WAL replayed after
+			 * the checkpoint.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
+			{
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--IxHwtWaH/DA3wSaA--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint
@ 2026-03-31 10:43 Adam Lee <adam8157@gmail.com>
  0 siblings, 0 replies; 645+ messages in thread

From: Adam Lee @ 2026-03-31 10:43 UTC (permalink / raw)

When recovery_target_action=shutdown triggers, the checkpointer performs
a shutdown restartpoint via CreateRestartPoint. If a new CHECKPOINT
record was replayed shortly before the recovery target, the restartpoint
advances minRecoveryPoint to the end of that CHECKPOINT record. And the
following replay doesn't advance minRecoveryPoint, it's assumed that
flushing the buffers will do that as a side-effect.

But no-op records replayed after the CHECKPOINT (such as RESTORE_POINT) do
not dirty any pages, so the minRecoveryPoint is not updated as expected.
As a result, minRecoveryPoint in pg_control ends up behind the actual
replay position. This does not cause a recovery correctness issue,
however the inaccurate pg_controldata "Minimum recovery ending location"
prevents users or tools from using this value to verify that recovery
has reached a specific restore point.

Fix by reading the current replay position from shared memory and
advancing minRecoveryPoint to match it. Since the replay position is
always at least as far as the checkpoint end, this also subsumes the
previous lastCheckPointEndPtr update.

Reproducer:
  CHECKPOINT; SELECT pg_create_restore_point('test_rp');
  -- recover with recovery_target_name + recovery_target_action=shutdown
  -- pg_controldata shows minRecoveryPoint 104 bytes behind
---
 src/backend/access/transam/xlog.c | 31 +++++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 8 deletions(-)

diff --git a/src/backend/access/transam/xlog.c b/src/backend/access/transam/xlog.c
index 2c1c6f88b74..ff9e373c4fa 100644
--- a/src/backend/access/transam/xlog.c
+++ b/src/backend/access/transam/xlog.c
@@ -7721,7 +7721,6 @@ bool
 CreateRestartPoint(int flags)
 {
 	XLogRecPtr	lastCheckPointRecPtr;
-	XLogRecPtr	lastCheckPointEndPtr;
 	CheckPoint	lastCheckPoint;
 	XLogRecPtr	PriorRedoPtr;
 	XLogRecPtr	receivePtr;
@@ -7737,7 +7736,6 @@ CreateRestartPoint(int flags)
 	/* Get a local copy of the last safe checkpoint record. */
 	SpinLockAcquire(&XLogCtl->info_lck);
 	lastCheckPointRecPtr = XLogCtl->lastCheckPointRecPtr;
-	lastCheckPointEndPtr = XLogCtl->lastCheckPointEndPtr;
 	lastCheckPoint = XLogCtl->lastCheckPoint;
 	SpinLockRelease(&XLogCtl->info_lck);
 
@@ -7864,15 +7862,32 @@ CreateRestartPoint(int flags)
 		 */
 		if (ControlFile->state == DB_IN_ARCHIVE_RECOVERY)
 		{
-			if (ControlFile->minRecoveryPoint < lastCheckPointEndPtr)
+			/*
+			 * Advance minRecoveryPoint to at least the current replay
+			 * position.  Normally this happens as a side effect of
+			 * flushing dirty buffers, but during a shutdown restartpoint
+			 * there may be records between the checkpoint and the
+			 * recovery target that didn't dirty any buffers (e.g. a
+			 * RESTORE_POINT record).  Without this, a shutdown triggered
+			 * by recovery_target_action leaves minRecoveryPoint behind
+			 * the actual replay position.
+			 */
 			{
-				ControlFile->minRecoveryPoint = lastCheckPointEndPtr;
-				ControlFile->minRecoveryPointTLI = lastCheckPoint.ThisTimeLineID;
+				XLogRecPtr	replayPtr;
+				TimeLineID	replayTLI;
 
-				/* update local copy */
-				LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
-				LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+				replayPtr = GetCurrentReplayRecPtr(&replayTLI);
+				if (ControlFile->minRecoveryPoint < replayPtr)
+				{
+					ControlFile->minRecoveryPoint = replayPtr;
+					ControlFile->minRecoveryPointTLI = replayTLI;
+				}
 			}
+
+			/* update local copy */
+			LocalMinRecoveryPoint = ControlFile->minRecoveryPoint;
+			LocalMinRecoveryPointTLI = ControlFile->minRecoveryPointTLI;
+
 			if (flags & CHECKPOINT_IS_SHUTDOWN)
 				ControlFile->state = DB_SHUTDOWNED_IN_RECOVERY;
 		}
-- 
2.47.3


--rlqg/1ddaRuGTcZI--





^ permalink  raw  reply  [nested|flat] 645+ messages in thread

* [PATCH v2 8/9] convert ParallelBlockTableScanDescData->phs_{start,num}block to atomics
@ 2026-07-09 20:21 Nathan Bossart <nathan@postgresql.org>
  0 siblings, 0 replies; 645+ messages in thread

From: Nathan Bossart @ 2026-07-09 20:21 UTC (permalink / raw)

---
 src/backend/access/heap/heapam_handler.c |  2 +-
 src/backend/access/table/tableam.c       | 59 +++++++++++-------------
 src/include/access/relscan.h             |  8 ++--
 3 files changed, 31 insertions(+), 38 deletions(-)

diff --git a/src/backend/access/heap/heapam_handler.c b/src/backend/access/heap/heapam_handler.c
index bf87430cf01..0f24a132564 100644
--- a/src/backend/access/heap/heapam_handler.c
+++ b/src/backend/access/heap/heapam_handler.c
@@ -1965,7 +1965,7 @@ heapam_scan_get_blocks_done(HeapScanDesc hscan)
 	if (hscan->rs_base.rs_parallel != NULL)
 	{
 		bpscan = (ParallelBlockTableScanDesc) hscan->rs_base.rs_parallel;
-		startblock = bpscan->phs_startblock;
+		startblock = pg_atomic_read_u32(&bpscan->phs_startblock);
 	}
 	else
 		startblock = hscan->rs_startblock;
diff --git a/src/backend/access/table/tableam.c b/src/backend/access/table/tableam.c
index 68ff0966f1c..f2038ea9205 100644
--- a/src/backend/access/table/tableam.c
+++ b/src/backend/access/table/tableam.c
@@ -421,9 +421,8 @@ table_block_parallelscan_initialize(Relation rel, ParallelTableScanDesc pscan)
 	bpscan->base.phs_syncscan = synchronize_seqscans &&
 		!RelationUsesLocalBuffers(rel) &&
 		bpscan->phs_nblocks > NBuffers / 4;
-	SpinLockInit(&bpscan->phs_mutex);
-	bpscan->phs_startblock = InvalidBlockNumber;
-	bpscan->phs_numblock = InvalidBlockNumber;
+	pg_atomic_init_u32(&bpscan->phs_startblock, InvalidBlockNumber);
+	pg_atomic_init_u32(&bpscan->phs_numblock, InvalidBlockNumber);
 	pg_atomic_init_u64(&bpscan->phs_nallocated, 0);
 
 	return sizeof(ParallelBlockTableScanDescData);
@@ -459,25 +458,22 @@ table_block_parallelscan_startblock_init(Relation rel,
 	StaticAssertDecl(MaxBlockNumber <= 0xFFFFFFFE,
 					 "pg_nextpower2_32 may be too small for non-standard BlockNumber width");
 
-	BlockNumber sync_startpage = InvalidBlockNumber;
 	BlockNumber scan_nblocks;
 
 	/* Reset the state we use for controlling allocation size. */
 	memset(pbscanwork, 0, sizeof(*pbscanwork));
 
-retry:
-	/* Grab the spinlock. */
-	SpinLockAcquire(&pbscan->phs_mutex);
-
 	/*
 	 * When the caller specified a limit on the number of blocks to scan, set
 	 * that in the ParallelBlockTableScanDesc, if it's not been done by
 	 * another worker already.
 	 */
-	if (numblocks != InvalidBlockNumber &&
-		pbscan->phs_numblock == InvalidBlockNumber)
+	if (numblocks != InvalidBlockNumber)
 	{
-		pbscan->phs_numblock = numblocks;
+		uint32		expected = InvalidBlockNumber;
+
+		pg_atomic_compare_exchange_u32(&pbscan->phs_numblock, &expected,
+									   numblocks);
 	}
 
 	/*
@@ -485,36 +481,35 @@ retry:
 	 * so now.  If a startblock was specified, start there, otherwise if this
 	 * is not a synchronized scan, we just start at block 0, but if it is a
 	 * synchronized scan, we must get the starting position from the
-	 * synchronized scan machinery.  We can't hold the spinlock while doing
-	 * that, though, so release the spinlock, get the information we need, and
-	 * retry.  If nobody else has initialized the scan in the meantime, we'll
-	 * fill in the value we fetched on the second time through.
+	 * synchronized scan machinery.
+	 *
+	 * If another worker initializes phs_startblock concurrently, just use
+	 * their value.
 	 */
-	if (pbscan->phs_startblock == InvalidBlockNumber)
+	if (pg_atomic_read_u32(&pbscan->phs_startblock) == InvalidBlockNumber)
 	{
+		BlockNumber newstartblock;
+		uint32		expected = InvalidBlockNumber;
+
 		if (startblock != InvalidBlockNumber)
-			pbscan->phs_startblock = startblock;
+			newstartblock = startblock;
 		else if (!pbscan->base.phs_syncscan)
-			pbscan->phs_startblock = 0;
-		else if (sync_startpage != InvalidBlockNumber)
-			pbscan->phs_startblock = sync_startpage;
+			newstartblock = 0;
 		else
-		{
-			SpinLockRelease(&pbscan->phs_mutex);
-			sync_startpage = ss_get_location(rel, pbscan->phs_nblocks);
-			goto retry;
-		}
+			newstartblock = ss_get_location(rel, pbscan->phs_nblocks);
+
+		pg_atomic_compare_exchange_u32(&pbscan->phs_startblock, &expected,
+									   newstartblock);
 	}
-	SpinLockRelease(&pbscan->phs_mutex);
 
 	/*
 	 * Figure out how many blocks we're going to scan; either all of them, or
 	 * just phs_numblock's worth, if a limit has been imposed.
 	 */
-	if (pbscan->phs_numblock == InvalidBlockNumber)
+	if (pg_atomic_read_u32(&pbscan->phs_numblock) == InvalidBlockNumber)
 		scan_nblocks = pbscan->phs_nblocks;
 	else
-		scan_nblocks = pbscan->phs_numblock;
+		scan_nblocks = pg_atomic_read_u32(&pbscan->phs_numblock);
 
 	/*
 	 * We determine the chunk size based on scan_nblocks.  First we split
@@ -595,10 +590,10 @@ table_block_parallelscan_nextpage(Relation rel,
 	 */
 
 	/* First, figure out how many blocks we're planning on scanning */
-	if (pbscan->phs_numblock == InvalidBlockNumber)
+	if (pg_atomic_read_u32(&pbscan->phs_numblock) == InvalidBlockNumber)
 		scan_nblocks = pbscan->phs_nblocks;
 	else
-		scan_nblocks = pbscan->phs_numblock;
+		scan_nblocks = pg_atomic_read_u32(&pbscan->phs_numblock);
 
 	/*
 	 * Now check if we have any remaining blocks in a previous chunk for this
@@ -644,7 +639,7 @@ table_block_parallelscan_nextpage(Relation rel,
 	if (nallocated >= scan_nblocks)
 		page = InvalidBlockNumber;	/* all blocks have been allocated */
 	else
-		page = (nallocated + pbscan->phs_startblock) % pbscan->phs_nblocks;
+		page = (nallocated + pg_atomic_read_u32(&pbscan->phs_startblock)) % pbscan->phs_nblocks;
 
 	/*
 	 * Report scan location.  Normally, we report the current page number.
@@ -658,7 +653,7 @@ table_block_parallelscan_nextpage(Relation rel,
 		if (page != InvalidBlockNumber)
 			ss_report_location(rel, page);
 		else if (nallocated == pbscan->phs_nblocks)
-			ss_report_location(rel, pbscan->phs_startblock);
+			ss_report_location(rel, pg_atomic_read_u32(&pbscan->phs_startblock));
 	}
 
 	return page;
diff --git a/src/include/access/relscan.h b/src/include/access/relscan.h
index 2ea06a67a63..2305d0159f3 100644
--- a/src/include/access/relscan.h
+++ b/src/include/access/relscan.h
@@ -19,7 +19,6 @@
 #include "nodes/tidbitmap.h"
 #include "port/atomics.h"
 #include "storage/relfilelocator.h"
-#include "storage/spin.h"
 #include "utils/relcache.h"
 
 
@@ -99,10 +98,9 @@ typedef struct ParallelBlockTableScanDescData
 	ParallelTableScanDescData base;
 
 	BlockNumber phs_nblocks;	/* # blocks in relation at start of scan */
-	slock_t		phs_mutex;		/* mutual exclusion for setting startblock */
-	BlockNumber phs_startblock; /* starting block number */
-	BlockNumber phs_numblock;	/* # blocks to scan, or InvalidBlockNumber if
-								 * no limit */
+	pg_atomic_uint32 phs_startblock;	/* starting block number */
+	pg_atomic_uint32 phs_numblock;	/* # blocks to scan, or InvalidBlockNumber
+									 * if no limit */
 	pg_atomic_uint64 phs_nallocated;	/* number of blocks allocated to
 										 * workers so far. */
 }			ParallelBlockTableScanDescData;
-- 
2.50.1 (Apple Git-155)


--Xf36GNcW+0xZNily
Content-Type: text/plain; charset=us-ascii
Content-Disposition: attachment;
	filename=v2-0009-convert-FastPathStrongRelationLocks-to-atomics.patch



^ permalink  raw  reply  [nested|flat] 645+ messages in thread


end of thread, other threads:[~2026-07-09 20:21 UTC | newest]

Thread overview: 645+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-03-31 10:43 [PATCH v2] Fix minRecoveryPoint not advanced past checkpoint in CreateRestartPoint Adam Lee <adam8157@gmail.com>
2026-07-09 20:21 [PATCH v2 8/9] convert ParallelBlockTableScanDescData->phs_{start,num}block to atomics Nathan Bossart <nathan@postgresql.org>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox