agora inbox for [email protected]help / color / mirror / Atom feed
COPY does not work with regproc and aclitem 513+ messages / 5 participants [nested] [flat]
* COPY does not work with regproc and aclitem @ 2006-10-23 19:43 Zdenek Kotala <[email protected]> 0 siblings, 2 replies; 513+ messages in thread From: Zdenek Kotala @ 2006-10-23 19:43 UTC (permalink / raw) To: pgsql-hackers I tried to use COPY command to export and import tables from catalog, but COPY command has problem with data type regproc. See example create table test (like pg_aggregate); copy pg_aggregate to '/tmp/pg_agg.out'; copy test from '/tmp/pg_agg.out'; ERROR: more than one function named "pg_catalog.avg" CONTEXT: COPY test, line 1, column aggfnoid: "pg_catalog.avg" The problem is that pg_proc table has following unique indexes: "pg_proc_oid_index" UNIQUE, btree (oid) "pg_proc_proname_args_nsp_index" UNIQUE, btree (proname, proargtypes, pronamespace) And regprocin in the backend/utils/adt/regproc.c cannot found unique OID for proname. Workaround is use binary mode, but on other side aclitem is not supported in the binary mode. postgres=# copy pg_class to '/tmp/pg_class.out' binary; ERROR: no binary output function available for type aclitem The solution is that COPY command will be use OID instead procname for export regproc. Zdenek ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 19:57 Andrew Dunstan <[email protected]> parent: Zdenek Kotala <[email protected]> 1 sibling, 1 reply; 513+ messages in thread From: Andrew Dunstan @ 2006-10-23 19:57 UTC (permalink / raw) To: Zdenek Kotala <[email protected]>; +Cc: pgsql-hackers Zdenek Kotala wrote: > I tried to use COPY command to export and import tables from catalog Is it just me or does this seem like a strange thing to want to do? I am trying to think of a good use case, so far without much success. cheers andrew ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:02 Alvaro Herrera <[email protected]> parent: Zdenek Kotala <[email protected]> 1 sibling, 1 reply; 513+ messages in thread From: Alvaro Herrera @ 2006-10-23 20:02 UTC (permalink / raw) To: Zdenek Kotala <[email protected]>; +Cc: pgsql-hackers Zdenek Kotala wrote: > I tried to use COPY command to export and import tables from catalog, > but COPY command has problem with data type regproc. See example > > create table test (like pg_aggregate); > copy pg_aggregate to '/tmp/pg_agg.out'; > copy test from '/tmp/pg_agg.out'; > > ERROR: more than one function named "pg_catalog.avg" > CONTEXT: COPY test, line 1, column aggfnoid: "pg_catalog.avg" Hmm, maybe it should be using regprocedure instead? That one emits type-qualified function names, IIRC. -- Alvaro Herrera http://www.CommandPrompt.com/ PostgreSQL Replication, Consulting, Custom Development, 24x7 support ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:03 Zdenek Kotala <[email protected]> parent: Andrew Dunstan <[email protected]> 0 siblings, 2 replies; 513+ messages in thread From: Zdenek Kotala @ 2006-10-23 20:03 UTC (permalink / raw) To: Andrew Dunstan <[email protected]>; +Cc: pgsql-hackers Andrew Dunstan wrote: > Zdenek Kotala wrote: >> I tried to use COPY command to export and import tables from catalog > > > Is it just me or does this seem like a strange thing to want to do? I am > trying to think of a good use case, so far without much success. > I'm playing with catalog upgrade. The very basic idea of my experiment is export data from catalog and import it back to the new initialized/fresh catalog. Zdenek ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:09 Tom Lane <[email protected]> parent: Alvaro Herrera <[email protected]> 0 siblings, 3 replies; 513+ messages in thread From: Tom Lane @ 2006-10-23 20:09 UTC (permalink / raw) To: Alvaro Herrera <[email protected]>; +Cc: Zdenek Kotala <[email protected]>; pgsql-hackers Alvaro Herrera <[email protected]> writes: > Hmm, maybe it should be using regprocedure instead? Not unless you want to break initdb. The only reason regproc still exists, really, is to accommodate loading of pg_type during initdb. Guess what: we can't do type lookup at that point. regards, tom lane ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:13 Alvaro Herrera <[email protected]> parent: Tom Lane <[email protected]> 2 siblings, 0 replies; 513+ messages in thread From: Alvaro Herrera @ 2006-10-23 20:13 UTC (permalink / raw) To: Tom Lane <[email protected]>; +Cc: Zdenek Kotala <[email protected]>; pgsql-hackers Tom Lane wrote: > Alvaro Herrera <[email protected]> writes: > > Hmm, maybe it should be using regprocedure instead? > > Not unless you want to break initdb. The only reason regproc still > exists, really, is to accommodate loading of pg_type during initdb. > Guess what: we can't do type lookup at that point. I was thinking in the copied-out table, which not necessarily has to be pg_aggregate. I just tried, and it works to do this: alvherre=# create table pg_aggregate2 (aggfnoid regprocedure, aggtransfn alvherre(# regprocedure, aggfinalfn regprocedure, aggsortop oid, aggtranstype oid, alvherre(# agginitval text); CREATE TABLE alvherre=# insert into pg_aggregate2 select * from pg_aggregate; INSERT 0 114 alvherre=# create table test (like pg_aggregate2); CREATE TABLE alvherre=# copy pg_aggregate2 to '/tmp/pg_agg.out'; COPY 114 alvherre=# copy test from '/tmp/pg_agg.out'; COPY 114 alvherre=# -- Alvaro Herrera http://www.CommandPrompt.com/ PostgreSQL Replication, Consulting, Custom Development, 24x7 support ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:16 Zdenek Kotala <[email protected]> parent: Tom Lane <[email protected]> 2 siblings, 1 reply; 513+ messages in thread From: Zdenek Kotala @ 2006-10-23 20:16 UTC (permalink / raw) To: Tom Lane <[email protected]>; +Cc: Alvaro Herrera <[email protected]>; pgsql-hackers Tom Lane wrote: > Alvaro Herrera <[email protected]> writes: >> Hmm, maybe it should be using regprocedure instead? > > Not unless you want to break initdb. The only reason regproc still > exists, really, is to accommodate loading of pg_type during initdb. > Guess what: we can't do type lookup at that point. Do you mean something like this: Datum regprocout(PG_FUNCTION_ARGS) { ... if( donot_resolve_procname == TRUE) { result = (char *) palloc(NAMEDATALEN); snprintf(result, NAMEDATALEN, "%u", proid); } ... PG_RETURN_CSTRING(result); } donot_resolve_procname will be set when COPY will be performed. Zdenek ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:17 Andrew Dunstan <[email protected]> parent: Zdenek Kotala <[email protected]> 1 sibling, 0 replies; 513+ messages in thread From: Andrew Dunstan @ 2006-10-23 20:17 UTC (permalink / raw) To: Zdenek Kotala <[email protected]>; +Cc: pgsql-hackers Zdenek Kotala wrote: > Andrew Dunstan wrote: >> Zdenek Kotala wrote: >>> I tried to use COPY command to export and import tables from catalog >> >> >> Is it just me or does this seem like a strange thing to want to do? I >> am trying to think of a good use case, so far without much success. >> > > I'm playing with catalog upgrade. The very basic idea of my experiment > is export data from catalog and import it back to the new > initialized/fresh catalog. > > > Fair enough, but I am somewhat doubtful that COPY is the best way to do this. cheers andrew ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:22 Tom Lane <[email protected]> parent: Zdenek Kotala <[email protected]> 1 sibling, 1 reply; 513+ messages in thread From: Tom Lane @ 2006-10-23 20:22 UTC (permalink / raw) To: Zdenek Kotala <[email protected]>; +Cc: Andrew Dunstan <[email protected]>; pgsql-hackers Zdenek Kotala <[email protected]> writes: > I'm playing with catalog upgrade. The very basic idea of my experiment > is export data from catalog and import it back to the new > initialized/fresh catalog. That is never going to work, at least not for any interesting catalogs. A system with a "fresh" (I assume you mean empty) pg_proc, for instance, is non functional. A much bigger problem, if you're thinking of this as a component step of pg_upgrade, is that you can't use anything at the COPY level of detail because it will fail if the new version wants a different catalog layout --- for instance, if someone's added a column to the catalog. The right way to implement pg_upgrade is to transfer the catalog data at the SQL-command level of abstraction, ie, "pg_dump -s" and reload. regards, tom lane ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:27 Tom Lane <[email protected]> parent: Zdenek Kotala <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Tom Lane @ 2006-10-23 20:27 UTC (permalink / raw) To: Zdenek Kotala <[email protected]>; +Cc: Alvaro Herrera <[email protected]>; pgsql-hackers Zdenek Kotala <[email protected]> writes: > if( donot_resolve_procname == TRUE) > { > result = (char *) palloc(NAMEDATALEN); > snprintf(result, NAMEDATALEN, "%u", proid); > } What for? If you want numeric OIDs you can have that today by casting the column to OID. More to the point, the issue is hardly restricted to COPY --- you'd get the same thing if you tried to insert data with INSERT. regards, tom lane ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:31 Zdenek Kotala <[email protected]> parent: Tom Lane <[email protected]> 0 siblings, 1 reply; 513+ messages in thread From: Zdenek Kotala @ 2006-10-23 20:31 UTC (permalink / raw) To: Tom Lane <[email protected]>; +Cc: Andrew Dunstan <[email protected]>; pgsql-hackers Tom Lane wrote: > Zdenek Kotala <[email protected]> writes: >> I'm playing with catalog upgrade. The very basic idea of my experiment >> is export data from catalog and import it back to the new >> initialized/fresh catalog. > > That is never going to work, at least not for any interesting catalogs. > A system with a "fresh" (I assume you mean empty) pg_proc, for instance, > is non functional. No empty, fresh initialized by initdb. I want to copy only "user data" which is not created during boostrap. > > A much bigger problem, if you're thinking of this as a component step > of pg_upgrade, is that you can't use anything at the COPY level of > detail because it will fail if the new version wants a different catalog > layout --- for instance, if someone's added a column to the catalog. Yes, I know about it. It is not problem, I want to prepare "shadow" catalog with new structure on old database in separate schema and adjust data in these tables. After it I want to make final COPY - data will be copied with correct structure. > The right way to implement pg_upgrade is to transfer the catalog data > at the SQL-command level of abstraction, ie, "pg_dump -s" and reload. I'm not sure if it is important, but I think that preserve OID is important and SQL level does not allow set OID. Zdenek ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:46 Andrew Dunstan <[email protected]> parent: Zdenek Kotala <[email protected]> 0 siblings, 1 reply; 513+ messages in thread From: Andrew Dunstan @ 2006-10-23 20:46 UTC (permalink / raw) To: Zdenek Kotala <[email protected]>; +Cc: Tom Lane <[email protected]>; pgsql-hackers Zdenek Kotala wrote: > Tom Lane wrote: > >> The right way to implement pg_upgrade is to transfer the catalog data >> at the SQL-command level of abstraction, ie, "pg_dump -s" and reload. > > I'm not sure if it is important, but I think that preserve OID is > important and SQL level does not allow set OID. > > Does it matter in any case other than where it refers to an on-disk object? And does that need anything other than a fixup to pg_class::relfilenode? cheers andrew ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: COPY does not work with regproc and aclitem @ 2006-10-23 20:57 Tom Lane <[email protected]> parent: Andrew Dunstan <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Tom Lane @ 2006-10-23 20:57 UTC (permalink / raw) To: Andrew Dunstan <[email protected]>; +Cc: Zdenek Kotala <[email protected]>; pgsql-hackers Andrew Dunstan <[email protected]> writes: > Zdenek Kotala wrote: >> I'm not sure if it is important, but I think that preserve OID is >> important and SQL level does not allow set OID. > Does it matter in any case other than where it refers to an on-disk > object? And does that need anything other than a fixup to > pg_class::relfilenode? The only things pg_upgrade should be trying to preserve OIDs for are large objects. I don't even see a need to worry about relfilenode: you've got to link the physical files into the new directory tree anyway, you can perfectly well link them in under whatever new relfilenode identity happens to be assigned during the dump-reload step. This was all worked out years ago. regards, tom lane ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: [HACKERS] COPY does not work with regproc and aclitem @ 2006-10-24 12:43 Zdenek Kotala <[email protected]> parent: Tom Lane <[email protected]> 2 siblings, 1 reply; 513+ messages in thread From: Zdenek Kotala @ 2006-10-24 12:43 UTC (permalink / raw) To: Tom Lane <[email protected]>; +Cc: Alvaro Herrera <[email protected]>; pgsql-hackers; [email protected] Tom Lane wrote: > Alvaro Herrera <[email protected]> writes: >> Hmm, maybe it should be using regprocedure instead? > > Not unless you want to break initdb. The only reason regproc still > exists, really, is to accommodate loading of pg_type during initdb. > Guess what: we can't do type lookup at that point. > I prepared patch which use oid output function instead regproc output. This change works only for COPY TO command. SELECT behavior is untouched. I extended copy regression test as well. Please, look on it if it is acceptable fix. With regards Zdenek Attachments: [text/x-patch] copy.patch (2.7K, ../../[email protected]/2-copy.patch) download | inline diff: Index: src/backend/commands/copy.c =================================================================== RCS file: /projects/cvsroot/pgsql/src/backend/commands/copy.c,v retrieving revision 1.271 diff -c -r1.271 copy.c *** src/backend/commands/copy.c 31 Aug 2006 03:17:50 -0000 1.271 --- src/backend/commands/copy.c 24 Oct 2006 12:35:45 -0000 *************** *** 1309,1315 **** &out_func_oid, &isvarlena); else ! getTypeOutputInfo(attr[attnum - 1]->atttypid, &out_func_oid, &isvarlena); fmgr_info(out_func_oid, &cstate->out_functions[attnum - 1]); --- 1309,1317 ---- &out_func_oid, &isvarlena); else ! /* For regproc datatype do not lookup proc name, use OID out function instead. ! It avoids problem with COPY FROM. */ ! getTypeOutputInfo(attr[attnum - 1]->atttypid == REGPROCOID? OIDOID : attr[attnum - 1]->atttypid, &out_func_oid, &isvarlena); fmgr_info(out_func_oid, &cstate->out_functions[attnum - 1]); Index: src/test/regress/input/copy.source =================================================================== RCS file: /projects/cvsroot/pgsql/src/test/regress/input/copy.source,v retrieving revision 1.14 diff -c -r1.14 copy.source *** src/test/regress/input/copy.source 2 May 2006 11:28:56 -0000 1.14 --- src/test/regress/input/copy.source 24 Oct 2006 12:35:46 -0000 *************** *** 105,107 **** --- 105,113 ---- copy copytest3 to stdout csv header; + --- test correct handling regproc data type + CREATE TEMP TABLE test_regproc (like pg_aggregate); + COPY pg_catalog.pg_aggregate TO '@abs_builddir@/results/test_regproc.data'; + COPY test_regproc FROM '@abs_builddir@/results/test_regproc.data'; + + select aggfnoid, cast(aggfnoid as oid) from pg_aggregate where aggfnoid=2147; Index: src/test/regress/output/copy.source =================================================================== RCS file: /projects/cvsroot/pgsql/src/test/regress/output/copy.source,v retrieving revision 1.12 diff -c -r1.12 copy.source *** src/test/regress/output/copy.source 2 May 2006 11:28:56 -0000 1.12 --- src/test/regress/output/copy.source 24 Oct 2006 12:35:46 -0000 *************** *** 70,72 **** --- 70,82 ---- c1,"col with , comma","col with "" quote" 1,a,1 2,b,2 + --- test correct handling regproc data type + CREATE TEMP TABLE test_regproc (like pg_aggregate); + COPY pg_catalog.pg_aggregate TO '@abs_builddir@/results/test_regproc.data'; + COPY test_regproc FROM '@abs_builddir@/results/test_regproc.data'; + select aggfnoid, cast(aggfnoid as oid) from pg_aggregate where aggfnoid=2147; + aggfnoid | aggfnoid + ------------------+---------- + pg_catalog.count | 2147 + (1 row) + ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: [HACKERS] COPY does not work with regproc and aclitem @ 2006-10-24 13:39 Tom Lane <[email protected]> parent: Zdenek Kotala <[email protected]> 0 siblings, 1 reply; 513+ messages in thread From: Tom Lane @ 2006-10-24 13:39 UTC (permalink / raw) To: Zdenek Kotala <[email protected]>; +Cc: Alvaro Herrera <[email protected]>; pgsql-hackers; [email protected] Zdenek Kotala <[email protected]> writes: > I prepared patch which use oid output function instead regproc output. > This change works only for COPY TO command. This is not a bug and we're not going to fix it, most especially not like that. regards, tom lane ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: [HACKERS] COPY does not work with regproc and aclitem @ 2006-10-26 13:31 Zdenek Kotala <[email protected]> parent: Tom Lane <[email protected]> 0 siblings, 1 reply; 513+ messages in thread From: Zdenek Kotala @ 2006-10-26 13:31 UTC (permalink / raw) To: Tom Lane <[email protected]>; +Cc: Alvaro Herrera <[email protected]>; pgsql-hackers; [email protected] Tom Lane napsal(a): > Zdenek Kotala <[email protected]> writes: >> I prepared patch which use oid output function instead regproc output. >> This change works only for COPY TO command. > > This is not a bug and we're not going to fix it, most especially not > like that. > OK, The behavior of regproc type is described in the documentation, but if we don't fix it, than Some error message like "Regproc data type is not supported by COPY TO command" could be useful. Because you find that something is wrong when you want to restore data back and it should be too late. Zdenek ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: [HACKERS] COPY does not work with regproc and aclitem @ 2006-10-26 13:44 Alvaro Herrera <[email protected]> parent: Zdenek Kotala <[email protected]> 0 siblings, 1 reply; 513+ messages in thread From: Alvaro Herrera @ 2006-10-26 13:44 UTC (permalink / raw) To: Zdenek Kotala <[email protected]>; +Cc: Tom Lane <[email protected]>; pgsql-hackers; [email protected] Zdenek Kotala wrote: > Tom Lane napsal(a): > >Zdenek Kotala <[email protected]> writes: > >>I prepared patch which use oid output function instead regproc output. > >>This change works only for COPY TO command. > > > >This is not a bug and we're not going to fix it, most especially not > >like that. > > OK, The behavior of regproc type is described in the documentation, but > if we don't fix it, than Some error message like "Regproc data type is > not supported by COPY TO command" could be useful. Because you find that > something is wrong when you want to restore data back and it should be > too late. But it works as "expected". If the approach you suggest would be one we would take, then it should emit the same error on SELECT as well, shouldn't we? I think the problem is that regproc COPY is not useful to you for your particular use case. But there are workarounds, like the one I suggested and you promptly ignored. -- Alvaro Herrera http://www.CommandPrompt.com/ The PostgreSQL Company - Command Prompt, Inc. ^ permalink raw reply [nested|flat] 513+ messages in thread
* Re: [HACKERS] COPY does not work with regproc and aclitem @ 2006-10-26 14:11 Zdenek Kotala <[email protected]> parent: Alvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Zdenek Kotala @ 2006-10-26 14:11 UTC (permalink / raw) To: Alvaro Herrera <[email protected]>; +Cc: Tom Lane <[email protected]>; pgsql-hackers; [email protected] Alvaro Herrera napsal(a): > Zdenek Kotala wrote: >> Tom Lane napsal(a): >>> Zdenek Kotala <[email protected]> writes: >>>> I prepared patch which use oid output function instead regproc output. >>>> This change works only for COPY TO command. >>> This is not a bug and we're not going to fix it, most especially not >>> like that. >> OK, The behavior of regproc type is described in the documentation, but >> if we don't fix it, than Some error message like "Regproc data type is >> not supported by COPY TO command" could be useful. Because you find that >> something is wrong when you want to restore data back and it should be >> too late. > > But it works as "expected". If the approach you suggest would be one we > would take, then it should emit the same error on SELECT as well, > shouldn't we? It is right. > I think the problem is that regproc COPY is not useful to you for your > particular use case. But there are workarounds, like the one I > suggested and you promptly ignored. Yes, I read your suggestion It is useful form me thanks for that. But I thought how to remove that regproc limitation or how to avoid some confusing. Current mention about regproc limitation/behavior in the documentation is really best solution. By the way, If I read carefully your suggestion, Tom's answer and documentation, correct solution (theoretical) is replace regproc by regprocedure datatype in the catalog, but there is problem in the boostrap phase? Thanks Zdenek ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 513+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 513+ messages in thread
end of thread, other threads:[~2026-05-18 17:13 UTC | newest] Thread overview: 513+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2006-10-23 19:43 COPY does not work with regproc and aclitem Zdenek Kotala <[email protected]> 2006-10-23 19:57 ` Andrew Dunstan <[email protected]> 2006-10-23 20:03 ` Zdenek Kotala <[email protected]> 2006-10-23 20:17 ` Andrew Dunstan <[email protected]> 2006-10-23 20:22 ` Tom Lane <[email protected]> 2006-10-23 20:31 ` Zdenek Kotala <[email protected]> 2006-10-23 20:46 ` Andrew Dunstan <[email protected]> 2006-10-23 20:57 ` Tom Lane <[email protected]> 2006-10-23 20:02 ` Alvaro Herrera <[email protected]> 2006-10-23 20:09 ` Tom Lane <[email protected]> 2006-10-23 20:13 ` Alvaro Herrera <[email protected]> 2006-10-23 20:16 ` Zdenek Kotala <[email protected]> 2006-10-23 20:27 ` Tom Lane <[email protected]> 2006-10-24 12:43 ` Zdenek Kotala <[email protected]> 2006-10-24 13:39 ` Tom Lane <[email protected]> 2006-10-26 13:31 ` Zdenek Kotala <[email protected]> 2006-10-26 13:44 ` Alvaro Herrera <[email protected]> 2006-10-26 14:11 ` Zdenek Kotala <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]>
This inbox is served by agora; see mirroring instructions for how to clone and mirror all data and code used for this inbox